Open redirect

Open redirects in C#

Description

Using a user-supplied URL as a redirect destination can send users to an untrusted external site.

Potential impact

  • Attackers can exploit a trusted domain for phishing, token theft or bypassing destination restrictions.

Remediation

Allow only local paths, or validate external destinations against an explicit list of trusted domains.

Examples

The first excerpt uses a Minimal API; the second belongs inside an MVC controller. Url, Redirect and LocalRedirect are controller APIs.

Before

csharp
return Results.Redirect(returnUrl);

After

csharp
if (!Url.IsLocalUrl(returnUrl)) {
    return Redirect("/dashboard");
}
return LocalRedirect(returnUrl);

Explanation:

  • Before: The user controls the redirect URL and can choose an attacker-controlled site.
  • After: Url.IsLocalUrl checks the destination first. Only an allowed local path is passed to LocalRedirect.

References