ProjectDiscovery's nuclei-templates repository received new detection templates for two open redirect vulnerabilities: CVE-2025-54793 in Astro SSR and CVE-2025-58044 in JumpServer. The Astro SSR issue abuses trailing-slash redirect behavior with double-slash path variations to trigger protocol-relative redirects, and the proposed template uses out-of-band validation through interact.sh to confirm exploitation. Review feedback flagged template quality problems, including an incorrect reference to the upstream fix commit and a Location header regex that could match benign redirects and produce false positives.
A separate template for JumpServer targets an unauthenticated open redirect caused by manipulation of the Referer header. Review notes said the check was validated against both vulnerable and patched targets and confirmed exploitation by requiring an HTTP 302 response and a malicious Location header pattern instead of relying only on version fingerprinting. The associated advisory metadata links the flaw to CWE-601 and GHSA-h762-mj7p-jwjq, underscoring continued efforts to improve reliable detection coverage for web application redirect weaknesses.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A pull request to projectdiscovery/nuclei-templates added a detection template for CVE-2025-58044, an unauthenticated open redirect in JumpServer triggered through the Referer header. Review notes said the template validated exploitation by checking for a 302 response and malicious Location header behavior, with no security issues found in the template itself.
A pull request to projectdiscovery/nuclei-templates added detection logic for CVE-2025-54793, using double-slash path variations and interact.sh to detect the open redirect behavior. Automated review flagged an incorrect fix-commit reference and a regex matcher that could cause false positives.
Astro addressed CVE-2025-54793, an open redirect vulnerability in Astro SSR. The referenced fix commit was identified as 0567fb7b50c0c452be387dd7c7264b96bedab48f.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.