Home

Description

An open redirect in the /api/google/authorize endpoint of hunvreus DevPush v0.3.2 allows attackers to redirect users to malicious sites via supplying a crafted URL.

PUBLISHED Reserved 2026-03-04 | Published 2026-04-27 | Updated 2026-04-27 | Assigner mitre

References

github.com/hunvreus/devpush

github.com/hunvreus/devpush/releases/tag/0.3.2

gist.github.com/syphonetic/d4e519904aaa55dbd0e3b87a317660d1

cve.org (CVE-2026-30346)

nvd.nist.gov (CVE-2026-30346)

Download JSON