CVE-2026-33885: Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential
Impact The external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows.
Patches This has been fixed in 5.73.16 and 6.7.2.
Other sources
Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33885?
CVE-2026-33885 is considered a high-severity vulnerability due to the potential for malicious redirection to external URLs.
How do I fix CVE-2026-33885?
To fix CVE-2026-33885, upgrade the Statamic CMS to version 5.73.16 or 6.7.2.
What type of software is affected by CVE-2026-33885?
CVE-2026-33885 affects the Statamic CMS software, specifically versions between 6.0.0.alpha.1 and 6.7.2 and all versions prior to 5.73.16.
What issue does CVE-2026-33885 involve?
CVE-2026-33885 involves a vulnerability in redirect validation on unauthenticated endpoints that can be bypassed.
What actions could lead to exploitation of CVE-2026-33885?
CVE-2026-33885 can be exploited after actions like form submissions and authentication flows, allowing for malicious redirects.