PT-2026-39215 · Kargo · Kargo

Pontushanssen

·

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2026-42350

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kargo versions prior to 1.7.10 Kargo versions prior to 1.8.13 Kargo versions prior to 1.9.8 Kargo versions prior to 1.10.2
Description Kargo, which manages and automates the promotion of software artifacts, contains an open redirect in the UI OIDC login flow. This occurs via the redirectTo query parameter.
Recommendations Update to version 1.7.10. Update to version 1.8.13. Update to version 1.9.8. Update to version 1.10.2.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42350

Affected Products

Kargo