Junglewise Threat Intelligence

CVE-2026-12863: Pretix Venueless open redirect in social login functionality

CVE-2026-12863 · Severity: info · CVSS 5.1 · Published 2026-06-22

Technologies: Pretix Venueless. Vendors: Pretix.

Executive brief

Venueless, a platform for virtual events, contains a security flaw in its social login feature. An attacker can create a malicious link that appears to be a legitimate login page but redirects the user to a fraudulent website after they sign in. This can be used in phishing campaigns to trick users into visiting malicious sites while believing they are still on a trusted domain.

Technical details

An open redirect vulnerability (CWE-601) exists in the social login component of Venueless. The application fails to properly validate the destination URL in the redirect parameter after a user completes the social authentication process. A remote attacker can craft a URL that leverages the trusted domain of the Venueless instance to redirect authenticated users to an arbitrary external site. Exploitation requires the attacker to have low privileges and for a victim to interact with the malicious link. The issue has been addressed in commit d27864a7.

Affected products

  • pretix Venueless < d27864a7 (git)

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory
  • 2026-06-22: patched

References

Related threats