Open Redirect in e621ng Affects Navigation Links
CVE-2026-95813

5.3MEDIUM

Key Information:

Vendor

E621ng

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-95813?

In e621ng versions prior to 26.09.16, a security flaw allows attackers to manipulate untrusted request parameters sent to the Rails 'url_for' method within the PaginatorComponent. This vulnerability enables the redirection of pagination and navigation controls to malicious sites by exploiting host, protocol, and port query parameters. As a result, legitimate pagination links can lead users to attacker-controlled domains while the original page appears to load from the trusted source, posing significant security risks.

Affected Version(s)

e621ng 0 < 26.09.16

e621ng 26.09.16

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zian F. do Vale
.