PT-2025-35317 · Basecamp · Google Sign In

·

CVE-2025-58067

·

Published

2025-08-29

·

Updated

2025-08-31

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Basecamp's google sign in gem versions prior to 1.3.1
Description The gem persists a URL for redirection after authentication. If this URL is set to a protocol-relative URL, it improperly passes the "same origin" check, potentially redirecting a user to another origin after authentication. This could result in exposure of authentication information if chained with other attacks that modify OAuth2 request parameters. Any Rails applications using the gem may be vulnerable if this vector can be chained with another attack.
Recommendations Update to version 1.3.1 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-58067
GHSA-5JCH-XHW4-R43V

Affected Products

Google Sign In