Skip to content

Open redirects: how attackers chain benign redirects to steal OAuth authorization codes and tokens

Why open redirect vulnerabilities are more dangerous than they appear: OAuth token interception, SSRF escalation, and credential phishing attack chains.

By BugSnaps Security Research · · 7 min read

Developers frequently treat open redirect vulnerabilities as minor low-severity cosmetic issues. In isolation, a parameter like `GET /login?redirect_url=https://attacker.com` merely sends a visitor to an external website. However, when chained with modern authentication protocols like OAuth 2.0, open redirects routinely result in complete account takeover.

The OAuth 2.0 authorization code theft chain

Many OAuth identity providers permit wildcard redirect URIs within a trusted domain (e.g., `https://app.example.com/*`). If `app.example.com` contains an open redirect endpoint, an attacker can craft an OAuth authorization request pointing to that redirect URL.

  • Authorization code leakage: the identity provider validates that the redirect domain matches `app.example.com` and appends the secret authorization code to the URL query string.
  • External relay: the open redirect immediately forwards the browser—along with the sensitive code parameter—to the attacker's harvesting server.
  • Token exchange: the attacker trades the stolen authorization code for an active user session token.

Preventing open redirects

Never redirect to arbitrary user-supplied URLs. Enforce relative-only redirects (verifying that the target begins with a single `/` and not `//` or `/`), or validate target URLs against a strict server-side allowlist of trusted destinations.

Never trust unvalidated redirect parameters. An open redirect is the primary building block for OAuth code theft and SSRF bypass chains.

Run a real pentest on your app - free.

Sign in, prove you own the domain, and MyPentest maps and tests it. No credit card.