CVE-2026-93871: Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix

Published Sep 18, 2026
·
Updated

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.

Affected Software

1 affected component
Cotonti<=1.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Update Cotonti to validate redirect destinations for page bodies using the redir: prefix so redirect targets cannot be stored to arbitrary external hosts.

    Cotonti (Stored Open Redirect via Page redir: Prefix) redirect destination validation for page bodies prefixed with redir: = validated (reject arbitrary external hosts)

Event History

Sep 18, 2026
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user who has permission to create or edit pages can exploit it. Administrative privileges are not required.

2

What must an attacker do to use the vulnerability?

The attacker must create or modify a page body to use the redir: prefix with an arbitrary external destination. A visitor must then follow the trusted-site page and be redirected.

3

Are unauthenticated visitors at risk?

Visitors do not need to be authenticated to be affected by a malicious stored redirect, but exploitation requires an authenticated user with page creation or editing permissions to plant it.

4

How can I check for existing malicious redirects?

Review page bodies created or edited by users with page permissions for use of the redir: prefix, particularly where it points to external hosts. Pages using that prefix can redirect visitors away from the trusted site.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203