Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. kiwitcms
  4. ›
  5. CVE-2026-54724

CVE-2026-54724: Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint

July 6, 2026

An open redirect vulnerability in the account confirmation endpoint allows an unauthenticated attacker to craft a URL hosted on a legitimate Kiwi TCMS instance that redirects victims to an arbitrary external domain. The attack surface is particularly relevant for phishing campaigns targeting Kiwi TCMS users, as the malicious link originates from a trusted organizational hostname.

References

  • github.com/advisories/GHSA-hmj5-jm8h-h9fh
  • github.com/kiwitcms/Kiwi/releases/tag/v16.1
  • github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh
  • kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161
  • nvd.nist.gov/vuln/detail/CVE-2026-54724

Code Behaviors & Features

Detect and mitigate CVE-2026-54724 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 12.4.0

Solution

Unfortunately, there is no solution available yet.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Source file

pypi/kiwitcms/CVE-2026-54724.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 13 Jul 2026 00:19:46 +0000.