{"id":"CVE-2025-60935","title":"An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL","summary":"An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phis…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-601"],"vendor":"returnfi","product":"blitz","affected":["blitz = 1.17.0"],"published":"2025-12-24","updated":"2026-10-05","sourceUpdated":"2026-10-05T18:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-60935","references":[{"url":"https://gist.github.com/HEXER365/2e866b47d56585e1e59e7c16bf4b4db7","label":"cve@mitre.org"},{"url":"https://github.com/ReturnFI/Blitz","label":"cve@mitre.org"}],"tags":["nvd"],"epss":0.0019,"epssPercentile":0.07822,"ingestedAt":"2026-10-05T18:29:11.158Z","slug":"CVE-2025-60935","body":"## Overview\n\nAn open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.\n\n## Affected\n\n- `blitz = 1.17.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}