Description
A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
References (4)
Core 4
Core References
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.344855
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.344855
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.748072
Various Sources exploit
https://gist.github.com/RacerZ-fighting/39f230feb0e450ae54f0a80c63c5d924
Scores
CVSS v3
4.3
EPSS
0.0028
EPSS Percentile
19.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-601
Status
published
Products (1)
mwielgoszewski/doorman
< 0.6
Published
Feb 08, 2026
Tracked Since
Feb 18, 2026