CVE-2026-41513

MEDIUM

Horilla: Open Redirect via Unvalidated `next` Parameter in Notification Endpoints

Title source: cna
STIX 2.1

Description

Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.

Scores

CVSS v4 4.8
EPSS 0.0027
EPSS Percentile 17.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
horilla/horilla-hr <= 1.5.0
Published May 12, 2026
Tracked Since May 12, 2026