CVE-2026-53989 Details
Description
Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenticated users to attacker-controlled sites by injecting an unvalidated redirect query parameter. Attackers can craft a malicious link targeting the OIDC callback flow to capture authorization codes via the Referer header and conduct follow-up credential phishing against any Dockhand account after a legitimate login.
An open redirect vulnerability has been identified in Dockhand versions prior to 1.0.36, specifically within the OIDC initiation endpoint. This vulnerability allows unauthenticated remote attackers to redirect authenticated users to malicious sites by injecting an unvalidated redirect query parameter. Attackers can create a harmful link that exploits the OIDC callback flow, potentially capturing authorization codes through the Referer header. This could lead to credential phishing attacks against any Dockhand account after the user has logged in.
Users can upgrade to Dockhand version 1.0.36 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Finsys/dockhand/releases/tag/v1.0.36 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/dockhand-open-redirect-via-oidc-initiation-endpoint | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Finsys Dockhand | < 1.0.36 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion