Junglewise Threat Intelligence

CVE-2026-13163: Mailerup open redirect in click-tracking endpoint

CVE-2026-13163 · Severity: info · CVSS 5.3 · Published 2026-06-24

Executive brief

Mailerup, an email marketing platform, contains a vulnerability in its link-tracking system. An attacker can create a malicious link that appears to belong to a trusted Mailerup domain but automatically redirects the user to a harmful external website. This can be used in phishing campaigns to trick users into providing credentials or downloading malware by exploiting the trust associated with the original domain.

Technical details

An open redirect vulnerability exists in the `_safe_redirect` function of the click-tracking endpoint (`/c/<token>/`) in Mailerup versions prior to 1.0.0. The vulnerability stems from two primary issues: first, while the application validates URL schemes (blocking `javascript:` and `data:`), it fails to restrict the destination host to an authorized allowlist. Second, the application silently catches `signing.BadSignature` exceptions, allowing the redirect logic to proceed even if a valid signed token is not provided. A remote, unauthenticated attacker can exploit this by crafting a URL with a malicious `u` query parameter to redirect victims to arbitrary external sites.

Affected products

  • Mailerup Mailerup < 1.0.0

Timeline

  • 2026-06-23: patched: Fix committed in GitHub repository
  • 2026-06-24: disclosed: CVE published to NVD

References

Related threats