CVE Explorer
CVE-2026-21879
Kanboard is project management software focused on Kanban methodology. Versions 1.2.48 and below are vulnerable to an Open Redirect attack that allows malicious actors to redirect authenticated users to attacker-controlled websites. By crafting URLs such as //evil.com, attackers can bypass the filter_var($url, FILTER_VALIDATE_URL) validation check. This vulnerability could be exploited to conduct phishing attacks, steal user credentials, or distribute malware. The issue is fixed in version 1.2.4
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"kanboard","vendor":"kanboard","versions":[{"status":"affected","version":"< 1.2.49"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-601","description":"CWE-601: URL Redirection to Untrusted Site ('Open Redirect')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"https://github.com/kanboard/kanboard/commit/93bcae03301a6d34185a8dba977417e6b3de519f","tags":["x_refsource_MISC"],"url":"https://github.com/kanboard/kanboard/commit/93bcae03301a6d34185a8dba977417e6b3de519f"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/references/1
{"name":"https://github.com/kanboard/kanboard/releases/tag/v1.2.49","tags":["x_refsource_MISC"],"url":"https://github.com/kanboard/kanboard/releases/tag/v1.2.49"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/references/2
{"tags":["exploit"],"url":"https://github.com/kanboard/kanboard/security/advisories/GHSA-mhv9-7m9w-7hcq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/adp/0/references/0
{"name":"https://github.com/kanboard/kanboard/security/advisories/GHSA-mhv9-7m9w-7hcq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/kanboard/kanboard/security/advisories/GHSA-mhv9-7m9w-7hcq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5df1afe33ac93d6bbcb01154c5575527534f12b64454aa68f96d478eec5fad22 · sha256:5756950a3498c0ae… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.