REDHAT-BUG-2546603: XSS
DOM-based cross-site scripting (XSS) vulnerability in the Ansible Platform UI's /redirect route (project: ansible/ansible-ui, affected component: platform/main/Redirect.tsx). The vulnerable Redirect component and /redirect route were introduced in commit df1902cc on 2024-04-23, and the upstream devel branch still pointed to the confirmed UI commit as of 2026-10-06. The root cause is that the next query parameter in Redirect.tsx flows directly to location.href without validation, even though the UI already provides a validateUrlPath helper (in frontend/common/AnsibleLogin/validateUrlPath.ts) that rejects javascript:, data:, absolute, and protocol-relative URLs — this helper is used by the login component but is not applied to the Redirect component, which is registered in usePlatformNavigation.tsx and exposed to authenticated users behind PlatformLogin after a valid Gateway session.