Cybersecurity

Open Redirect

/ˈəʊpən rɪˈdaɪrekt/

Definition

A vulnerability where a URL parameter controls the redirect destination, allowing phishing attacks via trusted domains.

Example in context

"Validate redirect_to against an allowlist — open redirects let attackers phish via your trusted login page URL."

Practice this term

Master Open Redirect in context by working through exercises in the Cybersecurity module. You'll see the term used in real engineering scenarios with multiple-choice, fill-in-the-blank, and matching drills.