
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33885 is an open redirect vulnerability in Statamic CMS, a Laravel and Git-powered content management system, caused by a URL parsing differential that allows bypass of external URL detection on unauthenticated endpoints. Attackers can exploit this to redirect users to arbitrary external URLs following actions such as form submissions and authentication flows. The vulnerability affects all Statamic versions prior to 5.73.16 and versions 6.0.0 through 6.7.1. It was published on March 24, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (GitHub Advisory, Statamic Advisory).
The root cause is classified as CWE-601 (URL Redirection to Untrusted Site / Open Redirect). The vulnerability stems from a differential in how the application parses URLs during redirect validation — the external URL detection logic on unauthenticated endpoints can be bypassed by crafting URLs that are interpreted differently by the validation layer versus the redirect handler. No authentication is required to trigger the flaw; however, user interaction is needed (e.g., a victim must click a crafted link or submit a form). The affected endpoints include authentication flows and form submission handlers (GitHub Advisory, Statamic Advisory).
Successful exploitation allows an attacker to redirect authenticated or unauthenticated users from a trusted Statamic site to an arbitrary external URL, enabling phishing attacks, credential harvesting, or malware delivery. The scope change in the CVSS score reflects that the impact crosses security boundaries — users trusting the legitimate Statamic domain may be silently sent to attacker-controlled infrastructure. Confidentiality and integrity are both assessed as low impact, and availability is unaffected (GitHub Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.037–0.052%, placing it in the 17th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires no privileges but does require user interaction, limiting its severity relative to fully unauthenticated, no-interaction vulnerabilities (GitHub Advisory, Statamic Advisory).
//evil.com, https:evil.com, or Unicode/encoded variants that fool the validator but are followed by the redirect handler.redirect, return, or similar parameters containing external URLs or obfuscated variants (e.g., //, %2F%2F, Unicode-encoded hostnames).Statamic has released patched versions 5.73.16 and 6.7.2 that correct the URL parsing differential used to bypass external redirect validation. Users should upgrade to one of these versions immediately. No official configuration-based workaround has been published; upgrading is the recommended and only confirmed remediation (GitHub Advisory, Statamic Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."