CVE-2026-95813: e621ng before 26.09.16 Open Redirect via URL Parameters

Published Sep 22, 2026
·
Updated

e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails urlfor in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation controls to attacker-controlled origins. Attackers can supply host, protocol, and port query parameters that are interpreted as URL generation options, causing pagination links to point to malicious domains while the initial page loads from the legitimate site.

Affected Software

1 affected component
e621ng e621ng<26.09.16

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade e621ng to a version that resolves this vulnerability.

    Fixed in 26.09.16

Event History

Sep 22, 2026
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Instances of e621ng running a version earlier than 26.09.16 are exposed when users can be induced to visit a crafted URL. The attacker does not need privileges, but a user must interact with affected pagination or navigation controls.

2

What does an attacker need to exploit it?

An attacker needs to supply crafted host, protocol, or port query parameters in a URL to an affected e621ng instance. Those parameters can cause generated pagination and navigation links to target an attacker-controlled origin even though the initial page is served by the legitimate site.

3

Is the initial page itself redirected?

No. The initial page loads from the legitimate site; the attacker-controlled destination is introduced through pagination and navigation links generated on that page.

4

What is the available remediation?

Upgrade e621ng to version 26.09.16 or later. The affected behavior applies to versions before 26.09.16.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203