Input validation error in Shopware - #VU131950
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect users to an arbitrary URL.
The vulnerability exists due to improper input validation in the GET /api/oauth/sso/auth endpoint when handling requests without the expected SSO session state. A remote attacker can supply a crafted Referer header to redirect users to an arbitrary URL.
User interaction is required, and the endpoint also reflects the attacker-controlled target into the Location header and the HTML redirect body, including dangerous schemes such as javascript:.