Description
Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site domain to redirect users to attacker-controlled hosts through the ratings plugin or other redirect callers.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Apply Patch
AI Analysis

Impact

The vulnerability arises from the cot_url_check() function in Cotonti versions up to 1.0.0, where the validator employs a regular expression missing the end-of-string anchor. This oversight lets an attacker craft hostnames beginning with the legitimate site domain, causing the function to accept them as legitimate destinations. The effect is an open redirect that can carry users from the victim site to arbitrary, attacker-controlled URLs. The weakness aligns with CWE‑601, which addresses open redirect flaws that undermine user trust and may be used for phishing or session hijacking.

Affected Systems

The defect is present in Cotonti 1.0.0, affecting the core application and redirect callers such as the ratings plugin. The vendor is the Cotonti project and the affected release is explicitly version 1.0.0; no other releases are listed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the medium severity range, reflecting a non-critical threat but still meaningful in contexts where redirects are exposed to untrusted input. The EPSS score is less than 1%, so the likelihood of active exploitation is currently low and the vulnerability is not listed in CISA KEV. Attackers would most likely trigger the flaw by directing a user through the web application to a crafted redirect URL, leveraging the missing anchor in the regex. Because the vulnerability resides in an open plugin, an application update or disabling the plug-in mitigates the risk.

Generated by OpenCVE AI on September 19, 2026 at 16:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Cotonti 1.0.1 or later
  • Apply the patch delivered in pull request 1899
  • If unable to upgrade, disable the ratings plugin or any other component that invokes cot_url_check() until a fix is available.

Generated by OpenCVE AI on September 19, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti cotonti
Cotonti siena
Vendors & Products Cotonti cotonti
Cotonti siena

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site domain to redirect users to attacker-controlled hosts through the ratings plugin or other redirect callers.
Title Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-601
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Cotonti Cotonti Cotonti Siena Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:17.909Z

Reserved: 2026-09-18T19:39:36.562Z

Link: CVE-2026-93869

cve-icon Vulnrichment

Updated: 2026-09-21T15:15:37.667Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:34.787

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')