CVE-2026-55252: Openrundev Openrun
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
OpenRun is an open-source, self-hosted GitOps platform for deploying web apps and internal tools to Docker or Kubernetes. Prior to version 0.17.7, the restrictions on redirect URLs in openrun can be bypassed by attackers, leading to open redirect attacks. This issue has been patched in version 0.17.7.
Affected products
- Openrundev Openrun: before 0.17.7 (fixed in 0.17.7)
Published 2026-10-01. Last modified 2026-10-02.