5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Description
Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo query parameter. This issue has been patched in versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2.
Basic Information
ID
CVE-2026-42350
Source
GitHub_M
Published
May 8, 2026 at 22:35
Affected Product
Vendor
akuity
Product
kargo
Version
< 1.7.10
Affected Versions
akuity kargo < 1.7.10
akuity kargo >= 1.8.0-rc.1, < 1.8.13
akuity kargo >= 1.9.0-rc.1, < 1.9.8
akuity kargo >= 1.10.0-rc.1, < 1.10.2
akuity kargo >= 1.8.0-rc.1, < 1.8.13
akuity kargo >= 1.9.0-rc.1, < 1.9.8
akuity kargo >= 1.10.0-rc.1, < 1.10.2