Open Redirect in e621ng Affects Navigation Links
CVE-2026-95813
5.3MEDIUM
What is CVE-2026-95813?
In e621ng versions prior to 26.09.16, a security flaw allows attackers to manipulate untrusted request parameters sent to the Rails 'url_for' method within the PaginatorComponent. This vulnerability enables the redirection of pagination and navigation controls to malicious sites by exploiting host, protocol, and port query parameters. As a result, legitimate pagination links can lead users to attacker-controlled domains while the original page appears to load from the trusted source, posing significant security risks.
Affected Version(s)
e621ng 0 < 26.09.16
e621ng 26.09.16
