PT-2026-44459 · Speaker · Speaker

Fushuling

+1

·

Published

2026-05-28

·

Updated

2026-05-28

·

CVE-2026-45307

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Speakr versions prior to 0.8.20-alpha
Description Speakr is a self-hosted web application for transcribing audio recordings. The is safe url() helper function, used to validate post-login redirect targets, incorrectly applies urljoin(request.host url, target) before parsing, while the controller passes the raw target to the redirect() function. This allows a scheme-relative input, such as ////evil.com, to be validated as a same-host URL but interpreted by the browser as a network-path-relative redirect to an external attacker-controlled host via the Location header.
Recommendations Update to version 0.8.20-alpha.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45307

Affected Products

Speaker