CVE-2026-5467

Source
https://cve.org/CVERecord?id=CVE-2026-5467
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5467.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-5467
Aliases
Downstream
Related
Published
2026-04-03T11:45:10.187Z
Modified
2026-07-31T18:30:35.138470999Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Casdoor OAuth Authorization Request redirect
Details

A vulnerability was identified in Casdoor 2.356.0. Affected by this issue is some unknown functionality of the component OAuth Authorization Request Handler. Such manipulation of the argument redirect_uri leads to open redirect. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "2.356.0"
                },
                {
                    "last_affected": "2.356.0"
                }
            ]
        }
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/5xxx/CVE-2026-5467.json"
}
References

Affected packages

Git / github.com/casdoor/casdoor

Affected ranges

Type
GIT
Repo
https://github.com/casdoor/casdoor
Events
Database specific
{
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.356.0"
        },
        {
            "last_affected": "2.356.0"
        }
    ]
}

Affected versions

2.*
2.356.0
v2.*
v2.356.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-5467.json"