PT-2026-20864 · Go Chi · Chi

Published

2026-01-14

·

Updated

2026-02-24

·

CVE-2025-69725

CVSS v3.1

4.7

Medium

AC:L/AV:N/A:N/C:L/I:N/PR:N/S:C/UI:R
Name of the Vulnerable Software and Affected Versions go-chi/chi versions 5.2.2 and later
Description An Open Redirect issue exists in the RedirectSlashes function of the go-chi/chi web framework. This flaw allows attackers to create malicious URLs that redirect users to arbitrary external sites, potentially enabling phishing, credential theft, or other social engineering attacks. The issue impacts the ability of the application to properly validate and sanitize redirect targets.
Recommendations Versions 5.2.2 and later should be updated when a fix is available. As a temporary workaround, consider carefully reviewing and validating all redirect operations within the application to ensure they are not susceptible to manipulation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-69725
GHSA-MQQF-5WVP-8FH8
GO-2026-4316
OPENSUSE-SU-2026:10239-1

Affected Products

Chi