CVE-2026-95813
e621ng before 26.09.16 Open Redirect via URL Parameters
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation controls to attacker-controlled origins. Attackers can supply host, protocol, and port query parameters that are interpreted as URL generation options, causing pagination links to point to malicious domains while the initial page loads from the legitimate site.
| CWE | CWE-601 |
| Vendor | e621ng |
| Product | e621ng |
| Published | Sep 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for e621ng e621ng
Be the first to know when new medium vulnerabilities affecting e621ng e621ng are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
e621ng / e621ng
0 < 26.09.16
References
github.com: https://github.com/e621ng/e621ng/pull/2518 github.com: https://github.com/e621ng/e621ng/commit/e1a3930bf1750b02a23843ec88c33e2aa06e2a5e github.com: https://github.com/e621ng/e621ng/releases/tag/26.09.16 github.com: https://github.com/e621ng/e621ng/blob/26.09.02/app/components/paginator_component.rb github.com: https://github.com/e621ng/e621ng vulncheck.com: https://www.vulncheck.com/advisories/e621ng-before-26.09.16-open-redirect-via-url-parameters
Credits
Zian F. do Vale