All fixes

Fix an open redirect parameter

open-redirect-param

A redirect parameter accepts absolute external URLs, lending your domain's trust to a phishing page. Allow relative paths or a fixed list only.

Express

  1. 1 Validate all redirect parameters against an allowlist
  2. 2 Reject absolute URLs and protocol-relative URLs (//evil.com)
javascript
// Reject external redirects
app.get('/redirect', (req, res) => {
  const url = req.query.url;
  if (!url || !url.startsWith('/') || url.startsWith('//')) {
    return res.redirect('/');
  }
  res.redirect(url);
});

Does your app still have this?

Scan your domain