CVE-2025-63784 Overview
CVE-2025-63784 is an Open Redirect vulnerability in the OAuth callback handler of the Onlook web application version 0.2.32. The flaw resides in onlook/apps/web/client/src/app/auth/callback/route.ts, where the application trusts the X-Forwarded-Host header value without validation when constructing the post-authentication redirect URL. A remote attacker can supply a crafted X-Forwarded-Host header to redirect an authenticated user to an arbitrary external site under attacker control. The issue maps to CWE-601: URL Redirection to Untrusted Site and is primarily useful for phishing and credential theft campaigns targeting Onlook users.
Critical Impact
Attackers can hijack the OAuth redirect flow to deliver authenticated users to attacker-controlled phishing pages, enabling credential and session theft.
Affected Products
- Onlook web application version 0.2.32
- OAuth callback handler at onlook/apps/web/client/src/app/auth/callback/route.ts
- Deployments that forward or accept the X-Forwarded-Host header without validation
Discovery Timeline
- 2025-11-07 - CVE-2025-63784 published to the National Vulnerability Database
- 2026-06-17 - Record last modified in NVD
Technical Details for CVE-2025-63784
Vulnerability Analysis
The Onlook OAuth callback route builds its redirect target using the X-Forwarded-Host HTTP header supplied by the client-facing proxy chain. Because the handler does not validate the header against an allowlist of trusted hosts, any attacker who can set this header can control the destination of the post-authentication redirect. The behavior is a classic Open Redirect [CWE-601] occurring at a security-sensitive point in the authentication flow. Once the user completes the OAuth exchange, the browser follows the attacker-chosen Location response, which may host a cloned login page or a malicious payload. The vulnerability does not require any pre-existing session with the attacker's infrastructure and is reachable over the network with low complexity.
Root Cause
The root cause is unsafe trust in a client-controllable request header. HTTP headers such as X-Forwarded-Host are advisory and can be injected by any upstream requester unless the application is deployed behind a proxy that strips or rewrites them. Onlook 0.2.32 uses the header value directly when assembling the redirect URL instead of comparing it to a known-good hostname or pulling the canonical host from server configuration.
Attack Vector
An attacker crafts an OAuth initiation request to a legitimate Onlook deployment while setting X-Forwarded-Host to a domain they control, for example attacker.example. After the identity provider redirects the authenticated user back to the Onlook callback endpoint, the handler constructs the final redirect using the attacker-supplied host. The user's browser is then sent to the attacker's domain, which can present a convincing login prompt or deliver malware under the trust context of the originating Onlook workflow. Full technical details are documented in the Soohyun Tech CVE-2025-63784 Analysis and the Toss Bank Open Redirect Advisory.
Detection Methods for CVE-2025-63784
Indicators of Compromise
- Requests to /auth/callback containing an X-Forwarded-Host value that does not match the deployment's canonical hostname.
- HTTP 3xx responses from the Onlook callback endpoint with a Location header pointing to an external domain.
- Authentication events immediately followed by outbound navigation to newly registered or unexpected domains.
Detection Strategies
- Inspect reverse proxy and application access logs for X-Forwarded-Host headers whose values are not in the approved host allowlist.
- Correlate OAuth callback responses with their resulting redirect destinations and alert on mismatches with the known service domain.
- Deploy web application firewall rules to flag or block requests that set X-Forwarded-Host from untrusted upstream sources.
Monitoring Recommendations
- Continuously monitor edge proxy configuration to confirm X-Forwarded-Host is set authoritatively by the proxy, not passed through from clients.
- Track user-agent patterns and geographic anomalies in authentication flows that terminate at external domains.
- Alert on repeated callback requests from the same source that vary the X-Forwarded-Host value, indicating probing behavior.
How to Mitigate CVE-2025-63784
Immediate Actions Required
- Upgrade Onlook beyond version 0.2.32 once a fixed release is published by the vendor.
- Configure the fronting reverse proxy or load balancer to strip or overwrite the X-Forwarded-Host header on all inbound requests.
- Enforce a server-side allowlist of permitted redirect hosts within the OAuth callback handler.
Patch Information
No vendor advisory or patched version is listed in the NVD record for CVE-2025-63784 at the time of publication. Monitor the Onlook project repository and the referenced advisories for a formal fix.
Workarounds
- Hardcode the canonical application host into the callback route rather than deriving it from request headers.
- Validate any redirect destination against a strict allowlist and reject requests whose derived host does not match.
- Terminate TLS at a trusted proxy that sets X-Forwarded-Host to a known value and discards any client-provided version.
# Example NGINX hardening to neutralize client-supplied X-Forwarded-Host
server {
listen 443 ssl;
server_name app.example.com;
location / {
proxy_set_header Host $host;
proxy_set_header X-Forwarded-Host app.example.com;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass http://onlook_backend;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.