{"apiVersion":"1.0","identifier":"CVE-2026-49996","description":"SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy-s origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is a dedicated physical machine exposed on the internet only via Tor hidden services for the Source and Journalist interfaces, and optionally via remote SSH access over another Tor hidden service. A newsroom-s SecureDrop Workstation communicates only with its own dedicated SecureDrop Server. Version 1.3.1 fixes the issue.","publishedAt":"2026-08-20T19:16:53","lastModifiedAt":"2026-08-20T20:17:34","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49996","cvssScore":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","epssProbability":0.00239,"riskScore":0.38,"affectedProduct":"SecureDrop Client","affectedVersions":"<1.3.1","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49996","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49996","en":"https://www.redsauce.net/en/cves/CVE-2026-49996","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49996","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49996","de":"https://www.redsauce.net/de/cves/CVE-2026-49996","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49996","el":"https://www.redsauce.net/el/cves/CVE-2026-49996"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49996"}}