CVE-2025-58067
MEDIUMgoogle_sign_in < 1.3.1 - Open Redirect via Session Store 'proceed_to' Parameter
Title source: llmDescription
Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.1, it is possible to redirect a user to another origin if the "proceed_to" value in the session store is set to a protocol-relative URL. Normally the value of this URL is only written and read by the library or the calling application. However, it may be possible to set this session value from a malicious site with a form submission. Any Rails applications using the google_sign_in gem may be vulnerable, if this vector can be chained with another attack that is able to modify the OAuth2 request parameters. This issue has been patched in version 1.3.1. There are no workarounds.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_confirm
https://github.com/basecamp/google_sign_in/security/advisories/GHSA-5jch-xhw4-r43v
Issue Tracking x_refsource_misc
https://github.com/basecamp/google_sign_in/pull/75
Patch x_refsource_misc
https://github.com/basecamp/google_sign_in/commit/e97aef4626b1bcbd2c6f01f7dd25f12ac855d4cc
Release Notes x_refsource_misc
https://github.com/basecamp/google_sign_in/releases/tag/v1.3.1
Scores
CVSS v3
4.2
EPSS
0.0021
EPSS Percentile
11.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (2)
basecamp/google_sign_in
< 1.3.1
rubygems/google_sign_in
0 - 1.3.1RubyGems
Published
Aug 29, 2025
Tracked Since
Feb 18, 2026