CVE-2026-93869 MEDIUM

CVE-2026-93869: Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex

Vendor Cotonti
Product Cotonti
Weakness CWE-601 · Open redirect
Published September 18, 2026
Last update September 18, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site domain to redirect users to attacker-controlled hosts through the ratings plugin or other redirect callers.

Key dates

02Disclosure timeline

September 18, 2026 CVE published

Related vulnerabilities

04Related CVE