Medium Severity

Open redirect: Toradex

Description

Detects inbound emails containing links that exploit an open redirect vulnerability on toradex.com's /service/share endpoint. The rule identifies links with both 'target' and 'url' query parameters present, which triggers the redirect, while excluding legitimate cases where the destination URL itself points back to toradex.com.

References

No references.

Sublime Security
Created Oct 5th, 2026 • Last updated Oct 5th, 2026
Source
type.inbound
and any(body.links,
        .href_url.domain.root_domain == "toradex.com"
        and strings.icontains(.href_url.path, '/service/share')
        // the redirect only fires when both params are present
        and regex.icontains(.href_url.query_params, '(?:^|&)target=')
        and regex.icontains(.href_url.query_params, '(?:^|&)url=')
        // negate use of the redirect by toradex
        and not regex.icontains(.href_url.query_params,
                                '(?:^|&)url=[^&]*toradex\.com'
        )
)
MQL Rule Console
•Docs•Learning Labs

Playground

Test against your own EMLs or sample data.

Share

Post about this on your socials.

Get Started. Today.

Managed or self-managed. No MX changes.

Deploy and integrate a free Sublime instance in minutes.
Get Started