Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-49996— securedrop-proxy origin limitation can be bypassed with redirects

Quick assessment

Affected
freedomofpress securedrop-client
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SecureDrop Client 是专为记者设计的桌面应用程序,用于在 SecureDrop Workstation 上安全地与线人沟通并处理提交内容。在 1.3.1 版本之前,恶意的 SecureDrop 服务器可以通过响应跨域重定向来绕过 securedrop-proxy 的源限制。SecureDrop 服务器本身具备多层内置加固措施,且为一台专用物理设备,仅通过 Tor 隐藏服务向互联网暴露线人和记者接口,可选地还通过另一个 Tor 隐藏服务进行远程 SSH 访问。新闻编辑室的 SecureDrop Wor

CVSS 3.7 · Low EPSS 0.24% · P15

Affected Version Matrix 1

VendorProduct Version RangeStatus
freedomofpress securedrop-client < 1.3.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-49996

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
securedrop-proxy origin limitation can be bypassed with redirects
Source: CVE Program / CVE List V5
Vulnerability Description
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom's SecureDrop Workstation communicates only with its own dedicated SecureDrop Server. Version 1.3.1 fixes the issue.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
freedomofpress securedrop-client < 1.3.1 -

II. Public POCs for CVE-2026-49996

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-49996

登录查看更多情报信息。

Patches & Fixes for CVE-2026-49996 (1)

Vendor Advisories for CVE-2026-49996 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-49996

No comments yet


Leave a comment