CVE 6.1 MEDIUM

Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential_CVE-2026-33885

6.1 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.

Basic Information

ID CVE-2026-33885
Source GitHub_M
Published Mar 27, 2026 at 20:39
Modified Mar 31, 2026 at 14:00

Affected Product

Vendor statamic
Product cms
Version < 5.73.16
Affected Versions statamic cms < 5.73.16
statamic cms >= 6.0.0.alpha.1, < 6.7.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.