Register for the AI for Security Summit: Join Figma, Perplexity & Wiz
Vulnerability DatabaseGHSA-w228-rfpx-fhm4

GHSA-w228-rfpx-fhm4
Python vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-w228-rfpx-fhm4) is an Open Redirect vulnerability discovered in the cg package (pip), affecting versions <= 60.2.6. The issue was identified in the handling of the referrer header in the application and was patched in version 60.2.12. The vulnerability was published and reviewed on April 23, 2024 (GitHub Advisory).

Technical details

The vulnerability stems from improper validation of the referrer header in certain conditions within the application. The specific issue was identified in the invoice view functionality at cg/server/invoices/views.py line 173, where the application directly uses the referrer header for redirection without proper validation. The vulnerability has been assigned a CVSS v3.1 base score of 6.1 (Moderate severity) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N (GitHub Advisory).

Impact

The exploitation of this vulnerability could enable attackers to redirect users to malicious websites or phishing pages, potentially leading to the disclosure of sensitive information. The impact includes possible phishing attacks, malware distribution, and potential exploitation of other vulnerabilities (GitHub Advisory).

Exploitability

The vulnerability is exploitable by manipulating the referer header in HTTP requests. An attacker can modify the referer header to redirect users to arbitrary domains without any verification. The attack requires no special privileges but does need user interaction (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 60.2.12 of the cg package. Users should upgrade to this version or later to mitigate the risk (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61599HIGH8.8
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61596HIGH7.1
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61588MEDIUM6.5
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61589MEDIUM6.3
  • Python logoPython
  • djust
NoYesSep 16, 2026
CVE-2026-61597MEDIUM5.1
  • Python logoPython
  • djust
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management