CVE-2026-67350: URL Redirection to Untrusted Site ('Open Redirect') in s9y Serendipity
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.
AI Analysis
Technical Summary
CVE-2026-67350 is an open redirect vulnerability affecting Serendipity versions before 2.6.1. The issue exists in exit.php and is triggered when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can supply a malicious Base64-encoded url parameter to redirect users to arbitrary external sites without authentication. This can be abused to create trusted-looking URLs leveraging the legitimate blog domain, which may be used for phishing, malware distribution, or bypassing URL reputation filters. The CVSS 4.0 score is 2.1, reflecting low severity. There is no vendor advisory or patch currently available, and no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows unauthenticated attackers to redirect users to arbitrary external websites via a crafted URL. This can facilitate phishing attacks, malware delivery, or evasion of URL reputation systems by leveraging the trusted domain of the affected Serendipity blog. The impact is limited to user redirection and does not include direct compromise of the application or data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, administrators should consider disabling or reconfiguring the Track Exits plugin to avoid using the commentredirection set to s9y option. Additionally, educating users to be cautious of unexpected redirects from the blog domain can help mitigate risk.
CVE-2026-67350: URL Redirection to Untrusted Site ('Open Redirect') in s9y Serendipity
Description
Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters.
CVSS v4.0
Score 2.1low
Affected software
s9y
Serendipity
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67350 is an open redirect vulnerability affecting Serendipity versions before 2.6.1. The issue exists in exit.php and is triggered when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can supply a malicious Base64-encoded url parameter to redirect users to arbitrary external sites without authentication. This can be abused to create trusted-looking URLs leveraging the legitimate blog domain, which may be used for phishing, malware distribution, or bypassing URL reputation filters. The CVSS 4.0 score is 2.1, reflecting low severity. There is no vendor advisory or patch currently available, and no known exploits in the wild have been reported.
Potential Impact
The vulnerability allows unauthenticated attackers to redirect users to arbitrary external websites via a crafted URL. This can facilitate phishing attacks, malware delivery, or evasion of URL reputation systems by leveraging the trusted domain of the affected Serendipity blog. The impact is limited to user redirection and does not include direct compromise of the application or data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, administrators should consider disabling or reconfiguring the Track Exits plugin to avoid using the commentredirection set to s9y option. Additionally, educating users to be cautious of unexpected redirects from the blog domain can help mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-29T13:36:36.277Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6cb6cfb597da70a83e01fd
Added to database: 07/31/2026, 14:53:03 UTC
Last enriched: 07/31/2026, 15:14:23 UTC
Last updated: 09/14/2026, 22:01:36 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.