CVE-2026-5467 describes an open redirect vulnerability (CWE-601) in Casdoor 2.356.0, specifically within its OAuth Authorization Request Handler, which can be triggered by manipulating the redirect_uri argument. This Medium severity flaw (CVSS 4.3) is remotely exploitable with low complexity and no privileges required, but it necessitates user interaction and primarily impacts integrity by redirecting users to potentially malicious sites. While not yet observed in active exploitation (KEV: No), a public exploit is available, increasing its risk, though community discussion and media coverage are currently very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.356.0CPE matchmatch criteria | cpe:2.3:a:casbin:casdoor:2.356.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.