CVE-2026-106033: Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session.
Other sources
DOM-based cross-site scripting (XSS) vulnerability in the Ansible Platform UI's /redirect route (project: ansible/ansible-ui, affected component: platform/main/Redirect.tsx). The vulnerable Redirect component and /redirect route were introduced in commit df1902cc on 2024-04-23, and the upstream devel branch still pointed to the confirmed UI commit as of 2026-10-06. The root cause is that the next query parameter in Redirect.tsx flows directly to location.href without validation, even though the UI already provides a validateUrlPath helper (in frontend/common/AnsibleLogin/validateUrlPath.ts) that rejects javascript:, data:, absolute, and protocol-relative URLs — this helper is used by the login component but is not applied to the Redirect component, which is registered in usePlatformNavigation.tsx and exposed to authenticated users behind PlatformLogin after a valid Gateway session.
— Red Hat