CVE-2026-67350 Details
Description
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.
An open redirect vulnerability has been identified in Serendipity versions prior to 2.6.1, specifically in the exit.php file. This vulnerability allows unauthenticated attackers to redirect users to arbitrary external sites by sending a malicious Base64-encoded url parameter. The issue arises when the Track Exits plugin is active and configured to redirect comments through the blog's domain. Exploitation of this vulnerability could be used for phishing, malware distribution, or to bypass URL reputation filters.
Users are advised to update Serendipity to version 2.6.1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 31, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/s9y/Serendipity/security/advisories/GHSA-77rw-27c5-4hxm | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/serendipity-open-redirect-via-exit-php | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Serendipity | <= 2.6.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 1, 2026 | CVE Modified | CISA-ADP |
| Jul 31, 2026 | New CVE Received | [email protected] |
Volerion