Vulnerability Description
The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://gist.github.com/kasiasok/870933de18d1400fa8be88e1bcadec6c
- https://statamic.com/addons/alt-design/alt-redirects/release-notes
FAQ
What is CVE-2025-60868?
CVE-2025-60868 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not re...
How severe is CVE-2025-60868?
CVE-2025-60868 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60868?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.