Intel

AIKIDO-2025-10426

govuk-prototype-kit is vulnerable to Open Redirect

Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 1, 2025

52

Medium Risk

This Affects:

jsgovuk-prototype-kit
13.1.0 - 13.16.2
Fixed in 13.17.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Open Redirect due to improper sanitization of the returnURL query parameter in the login functionality. The vulnerability allows attackers to craft malicious links that redirect authenticated users to arbitrary external domains after login, as demonstrated by accessing a URL like https://myapp.com/manage-prototype/password?returnURL=%2F%2Fevil.com. Exploitation occurs when a victim logs in via such a manipulated link, enabling phishing attacks where the attacker can steal credentials or distribute malware by redirecting users to a malicious site under their control.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

govuk-prototype-kit is vulnerable to Open Redirect in versions 13.1.0 - 13.16.2.

How to fix this

Upgrade the govuk-prototype-kit library to the patch version.