Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. statamic/cms
  4. ›
  5. CVE-2026-33885

CVE-2026-33885: Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential

March 26, 2026

The external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows.

References

  • github.com/advisories/GHSA-7f74-7q5w-hj4r
  • github.com/statamic/cms
  • github.com/statamic/cms/security/advisories/GHSA-7f74-7q5w-hj4r
  • nvd.nist.gov/vuln/detail/CVE-2026-33885

Code Behaviors & Features

Detect and mitigate CVE-2026-33885 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 6.0.0.alpha.1 before 6.7.2, all versions before 5.73.16

Fixed versions

  • 5.73.16
  • 6.7.2

Solution

Upgrade to versions 5.73.16, 6.7.2 or above.

Impact 6.1 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Source file

packagist/statamic/cms/CVE-2026-33885.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 27 Mar 2026 12:18:43 +0000.