PT-2026-6981 · Mwielgoszewski · Doorman
Racerz
·
Published
2026-02-08
·
Updated
2026-04-06
·
CVE-2026-2153
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
mwielgoszewski doorman versions prior to 0.7
Description
A flaw exists in the
is safe url function within the doorman/users/views.py file. Manipulation of the Next argument can result in an open redirect. This issue can be exploited remotely. The exploit has been publicly disclosed.Recommendations
Update to version 0.7 or later.
As a temporary workaround, consider restricting or validating the
Next parameter to prevent redirection to untrusted URLs.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doorman