๐Ÿ” CVE Alert

CVE-2026-40039

MEDIUM 6.5

Pachno 1.0.6 Open Redirection via return_to Parameter

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
9th

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

CWE CWE-305
Vendor pancho
Product pachno
Published Apr 13, 2026
Last Updated Apr 16, 2026
Stay Ahead of the Next One

Get instant alerts for pancho pachno

Be the first to know when new medium vulnerabilities affecting pancho pachno are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

pancho / Pachno
1.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zeroscience.mk: https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5981.php vulncheck.com: https://www.vulncheck.com/advisories/pachno-open-redirection-via-return-to-parameter

Credits

LiquidWorm as Gjoko Krstic of Zero Science Lab