{"id":"CVE-2026-25198","aliases":["GHSA-rf8c-3f5p-xv45","PYSEC-2026-3413"],"title":"web2py has an Open Redirect Vulnerability","summary":"web2py has an Open Redirect Vulnerability","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N","vendor":"web2py","product":"web2py","ecosystem":"pip","affected":["web2py < 3.1.1"],"patched":["web2py 3.1.1"],"published":"2026-02-05","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-rf8c-3f5p-xv45","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25198"},{"url":"https://github.com/web2py/web2py/commit/b4e1ddbd6d40fb30863f6263a67bcdf411a0c6df"},{"url":"https://github.com/web2py/web2py"},{"url":"https://github.com/web2py/web2py/releases"},{"url":"https://jvn.jp/en/jp/JVN46925341"},{"url":"https://web2py.com"}],"tags":["osv","pip"],"epss":0.00306,"epssPercentile":0.23512,"ingestedAt":"2026-07-13T18:58:02.686Z","slug":"CVE-2026-25198","body":"## Overview\n\nweb2py versions 2.27.1-stable+timestamp.2023.11.16.08.03.57 and prior contain an Open Redirect vulnerability. If this vulnerability is exploited, the user may be redirected to an arbitrary website when accessing a specially crafted URL. As a result, the user may become a victim of a phishing attack.\n\n## Affected packages\n\n- `web2py < 3.1.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `web2py 3.1.1`","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}