Redirect Vulnerability in Statamic Content Management System
CVE-2026-33885

6.1MEDIUM

Key Information:

Vendor

Statamic

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33885?

The Statamic CMS, which utilizes Laravel and Git, has a vulnerability that affects its external URL detection mechanism. Prior to the updates in versions 5.73.16 and 6.7.2, the system allowed an attacker to bypass the redirect validation on unauthenticated endpoints. This flaw could lead to unauthorized redirection of users to external URLs after events like form submissions or authentication actions, posing a risk to user data and security. The issue has been addressed in the latest releases.

Affected Version(s)

cms < 5.73.16 < 5.73.16

cms >= 6.0.0.alpha.1, < 6.7.2 < 6.0.0.alpha.1, 6.7.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.