Open Redirect Vulnerability in Serendipity Product by s9y
CVE-2026-67350

2.1LOW

Key Information:

Vendor

S9y

Vendor
CVE Published:
31 July 2026

What is CVE-2026-67350?

An open redirect vulnerability exists in Serendipity prior to version 2.6.1, specifically in the exit.php file. This flaw allows unauthenticated attackers to manipulate the Base64-encoded url parameter, leading to unauthorized redirection of users to potentially harmful external sites. When the Track Exits plugin is configured with the commentredirection option set to s9y, attackers can exploit this vulnerability to create seemingly trustworthy URLs that appear to be from legitimate blog domains. This manipulation can be used for phishing attacks, malware distribution, or circumventing URL reputation filters, posing significant risks to user safety and website integrity.

Affected Version(s)

Serendipity 0 < 2.6.1

Serendipity 2.6.1

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vaibhav Kubade (@DevVaibhav07)
.