Executive brief
Horilla, an HR and CRM software suite, contains a security flaw in its notification system. An attacker can create a malicious link that appears to be a legitimate part of the Horilla application but instead redirects the user to an external, untrusted website. This can be used in phishing campaigns to trick employees into providing credentials or downloading malware on a site they believe is trusted.
Technical details
An open redirect vulnerability exists in Horilla 1.5.0 within the notification component. The application's notification endpoints, such as 'mark-all-as-read/', accept a 'next' query parameter and pass it directly to the Django redirect() function without performing validation (e.g., using url_has_allowed_host_and_scheme()). An attacker with low privileges can craft a URL that, when clicked by an authenticated user, performs the notification action and then redirects the victim to an arbitrary external domain. This flaw facilitates phishing and social engineering attacks by leveraging the reputation of the trusted application domain. A fix has been committed to the project's repository to validate the redirect target.
Affected products
- Horilla Horilla 1.5.0
Timeline
- 2026-04-27: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE published to NVD