Vulnerability Description
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm
- https://www.vulncheck.com/advisories/serendipity-open-redirect-via-exit-php
- https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm
FAQ
What is CVE-2026-67350?
CVE-2026-67350 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded...
How severe is CVE-2026-67350?
CVE-2026-67350 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-67350?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.