Junglewise Threat Intelligence

CVE-2026-95813: e621ng open redirect via url_for parameter injection in paginator

CVE-2026-95813 · Severity: medium · CVSS 6.1 · Published 2026-09-22

Executive brief

e621ng is a Rails-based image sharing and tagging platform. A vulnerability in versions before 26.09.16 allows attackers to inject malicious host, protocol, and port parameters into pagination and navigation links. Users clicking pagination controls can be redirected to attacker-controlled domains while the page initially loads from the legitimate site, enabling phishing and credential theft attacks.

Technical details

The PaginatorComponent and controller navigation pass untrusted query parameters directly to Rails url_for helper, allowing attackers to inject host, protocol, and port options that override the intended URL generation. This is a reflected open redirect vulnerability accessible to unauthenticated users through GET request parameters. The fix is to sanitize or whitelist pagination parameters before passing them to url_for.

Affected products

  • e621ng e621ng before 26.09.16

Timeline

  • 2026-09-22: disclosed

References