govuk-prototype-kit is vulnerable to Open Redirect
52
Medium Risk
Affected versions of this package are vulnerable to Open Redirect due to improper sanitization of the returnURL query parameter in the login functionality. The vulnerability allows attackers to craft malicious links that redirect authenticated users to arbitrary external domains after login, as demonstrated by accessing a URL like https://myapp.com/manage-prototype/password?returnURL=%2F%2Fevil.com. Exploitation occurs when a victim logs in via such a manipulated link, enabling phishing attacks where the attacker can steal credentials or distribute malware by redirecting users to a malicious site under their control.
You are affected if you are using a version that falls within the vulnerable range.
govuk-prototype-kit is vulnerable to Open Redirect in versions 13.1.0 - 13.16.2.
Upgrade the govuk-prototype-kit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant