Statamic is a Laravel and Git powered content management system (CMS). Prior to versions 5.73.16 and 6.7.2, the external URL detection used for redirect validation on unauthenticated endpoints could be bypassed, allowing users to be redirected to external URLs after actions like form submissions and authentication flows. This has been fixed in 5.73.16 and 6.7.2.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-27 21:17
Updated : 2026-03-30 13:26
NVD link : CVE-2026-33885
Mitre link : CVE-2026-33885
CVE.ORG link : CVE-2026-33885
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
