CVE-2026-2153

MEDIUM

mwielgoszewski doorman <0.6 - Open Redirect

Title source: llm
STIX 2.1

Description

A vulnerability was determined in mwielgoszewski doorman up to 0.6. This issue affects the function is_safe_url of the file doorman/users/views.py. Executing a manipulation of the argument Next can lead to open redirect. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
mwielgoszewski/doorman < 0.6
Published Feb 08, 2026
Tracked Since Feb 18, 2026