CVE-2026-28413: Products.isurlinportal has possible open redirect when using more than 2 forward slashes
(updated )
A url /login?came_from=////evil.example may redirect to an external website after login.
Standard Plone is not affected, but if you have customised the login, for example with add-ons, you might be affected. You can try the url to check if you are affected or not.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-28413 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →