CVE-2026-2709 is an open redirect vulnerability in busy up to version 2.5.5, specifically within the Callback Handler component of the server/app.js file. An attacker can remotely manipulate the 'state' argument to redirect users to arbitrary malicious sites. The vulnerability has a low CVSS score of 3.5, indicating a low impact with no confidentiality, integrity, or availability compromise, and requires user interaction. While an exploit has been published, there is no evidence of active exploitation, and it lacks exploit intelligence in common frameworks and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | Busy | 2.5.0, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.5.5CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.