PT-2026-20864 · Go Chi · Chi
Published
2026-01-14
·
Updated
2026-02-24
·
CVE-2025-69725
CVSS v3.1
4.7
Medium
| AC:L/AV:N/A:N/C:L/I:N/PR:N/S:C/UI:R |
Name of the Vulnerable Software and Affected Versions
go-chi/chi versions 5.2.2 and later
Description
An Open Redirect issue exists in the
RedirectSlashes function of the go-chi/chi web framework. This flaw allows attackers to create malicious URLs that redirect users to arbitrary external sites, potentially enabling phishing, credential theft, or other social engineering attacks. The issue impacts the ability of the application to properly validate and sanitize redirect targets.Recommendations
Versions 5.2.2 and later should be updated when a fix is available. As a temporary workaround, consider carefully reviewing and validating all redirect operations within the application to ensure they are not susceptible to manipulation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chi