---
id: CVE-2026-54724
title: Kiwi TCMS is an open source test management system
summary: >-
  Kiwi TCMS is an open source test management system. Prior to 16.1, the account
  confirmation endpoint accepted an unvalidated next parameter, allowing an
  unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that
  redire…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: kiwitcms
product: Kiwi
affected:
  - Kiwi < 16.1
published: '2026-09-15'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T17:17:21.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54724'
references:
  - url: >-
      https://github.com/kiwitcms/Kiwi/commit/93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06
    label: security-advisories@github.com
  - url: 'https://github.com/kiwitcms/Kiwi/releases/tag/v16.1'
    label: security-advisories@github.com
  - url: 'https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh'
    label: security-advisories@github.com
  - url: 'https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161'
  - url: 'https://github.com/advisories/GHSA-hmj5-jm8h-h9fh'
tags:
  - nvd
  - cve.org
  - ghsa
  - pip
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T16:53:12.255993Z'
aliases:
  - GHSA-hmj5-jm8h-h9fh
ecosystem: pip
ingestedAt: '2026-07-06T21:45:52.927Z'
epss: 0.00347
epssPercentile: 0.2559
---

## Overview

Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-54724)

Affected packages:

- `kiwitcms <= 112.4`

Source: https://github.com/advisories/GHSA-hmj5-jm8h-h9fh
