Developers frequently treat open redirect vulnerabilities as minor low-severity cosmetic issues. In isolation, a parameter like `GET /login?redirect_url=https://attacker.com` merely sends a visitor to an external website. However, when chained with modern authentication protocols like OAuth 2.0, open redirects routinely result in complete account takeover.
The OAuth 2.0 authorization code theft chain
Many OAuth identity providers permit wildcard redirect URIs within a trusted domain (e.g., `https://app.example.com/*`). If `app.example.com` contains an open redirect endpoint, an attacker can craft an OAuth authorization request pointing to that redirect URL.
- Authorization code leakage: the identity provider validates that the redirect domain matches `app.example.com` and appends the secret authorization code to the URL query string.
- External relay: the open redirect immediately forwards the browser—along with the sensitive code parameter—to the attacker's harvesting server.
- Token exchange: the attacker trades the stolen authorization code for an active user session token.
Preventing open redirects
Never redirect to arbitrary user-supplied URLs. Enforce relative-only redirects (verifying that the target begins with a single `/` and not `//` or `/`), or validate target URLs against a strict server-side allowlist of trusted destinations.
Never trust unvalidated redirect parameters. An open redirect is the primary building block for OAuth code theft and SSRF bypass chains.