216.73.217.80

CVE-2026-40039

· Published 13/04/2026 19:16 · Modified 13/04/2026 19:16

Labels: CVE-2026-40039 2026-04-13CVE-2026-40039CWE-305[email protected]

Essential information

Published
13/04/2026 19:16
Modified
13/04/2026 19:16
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Pachno 1.0.6 contains an open redirection vulnerability that allows attackers to redirect users to arbitrary external websites by manipulating the return_to parameter. Attackers can craft malicious login URLs with unvalidated return_to values to conduct phishing attacks and steal user credentials.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
pachno / pachno cpe:2.3:a:pachno:pachno:1.0.6:*:*:*:*:*:*:*

References