Vulnerability library
Security checkMay 11, 2026

Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpm@saltcorn/server

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Saltcorn validates the post-login dest parameter with a string check that only blocks :/ and //. Because all WHATWG-compliant browsers normalise backslashes (\) to forward slashes (/) for special schemes, a payload such as /\evil.com/path slips through is_relative_url(), is emitted unchanged in the HTTP Location header, and causes the browser to navigate cross-origin to an attacker-controlled domain.

Recommendation

Update the @saltcorn/server package to the latest compatible version. Followings are version details:

  • Affected version(s): **>= 1.6.0-alpha.0, < 1.6.0-beta.5 >= 1.5.0-beta.0, < 1.5.6 < 1.4.6**
  • Patched version(s): **1.6.0-beta.5 1.5.6 1.4.6**

References

Could your website be exposed too?

SmartScanner can check your website for Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated May 11, 2026