PT-2026-6981 · Mwielgoszewski · Doorman

Racerz

·

Published

2026-02-08

·

Updated

2026-04-06

·

CVE-2026-2153

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions mwielgoszewski doorman versions prior to 0.7
Description A flaw exists in the is safe url function within the doorman/users/views.py file. Manipulation of the Next argument can result in an open redirect. This issue can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Update to version 0.7 or later. As a temporary workaround, consider restricting or validating the Next parameter to prevent redirection to untrusted URLs.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2026-2153

Affected Products

Doorman