LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...

zetlyn/cve-ghsa vulnerability ghsa GHSA-4h8m-c92p-4pmv cve CVE-2026-105128 known 2026-10-04

https://github.com/advisories/GHSA-4h8m-c92p-4pmv

Properties

cvss5.4
receipt
Source
GitHub advisories
Its words
5.4
Read by
field:cvss.score
Said since
2026-10-04 06:10 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105128",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 5.3,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-601",
      "name": "URL Redirection to Untrusted Site ('Open Redirect')"
    }
  ],
  "description": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.",
  "ghsa_id": "GHSA-4h8m-c92p-4pmv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4h8m-c92p-4pmv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105128"
    }
  ],
  "nvd_published_at": "2026-10-04T00:16:36Z",
  "published_at": "2026-10-04T00:31:00Z",
  "references": [
    "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105128",
    "https://github.com/laradashboard/laradashboard/pull/341",
    "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66",
    "https://github.com/laradashboard/laradashboard",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762",
    "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8",
    "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url",
    "https://github.com/advisories/GHSA-4h8m-c92p-4pmv"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T00:31:07Z",
  "url": "https://api.github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
cweCWE-601
receipt
Source
GitHub advisories
Its words
CWE-601
Read by
field:cwes[].cwe_id
Said since
2026-10-04 06:10 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105128",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 5.3,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-601",
      "name": "URL Redirection to Untrusted Site ('Open Redirect')"
    }
  ],
  "description": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.",
  "ghsa_id": "GHSA-4h8m-c92p-4pmv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4h8m-c92p-4pmv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105128"
    }
  ],
  "nvd_published_at": "2026-10-04T00:16:36Z",
  "published_at": "2026-10-04T00:31:00Z",
  "references": [
    "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105128",
    "https://github.com/laradashboard/laradashboard/pull/341",
    "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66",
    "https://github.com/laradashboard/laradashboard",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762",
    "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8",
    "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url",
    "https://github.com/advisories/GHSA-4h8m-c92p-4pmv"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T00:31:07Z",
  "url": "https://api.github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "vulnerabilities": [],
  "withdrawn_at": null
}
severitymedium
receipt
Source
GitHub advisories
Its words
medium
Read by
field:severity
Said since
2026-10-04 06:10 UTC
Last answered
2026-10-04 18:15 UTC
Original
open at the source
What the source handed over
{
  "comments": 0,
  "credits": [],
  "cve_id": "CVE-2026-105128",
  "cvss": {
    "score": 5.4,
    "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
  },
  "cvss_severities": {
    "cvss_v3": {
      "score": 5.4,
      "vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
    },
    "cvss_v4": {
      "score": 5.3,
      "vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
    }
  },
  "cwes": [
    {
      "cwe_id": "CWE-601",
      "name": "URL Redirection to Untrusted Site ('Open Redirect')"
    }
  ],
  "description": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.",
  "ghsa_id": "GHSA-4h8m-c92p-4pmv",
  "github_reviewed_at": null,
  "html_url": "https://github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "identifiers": [
    {
      "type": "GHSA",
      "value": "GHSA-4h8m-c92p-4pmv"
    },
    {
      "type": "CVE",
      "value": "CVE-2026-105128"
    }
  ],
  "nvd_published_at": "2026-10-04T00:16:36Z",
  "published_at": "2026-10-04T00:31:00Z",
  "references": [
    "https://github.com/laradashboard/laradashboard/security/advisories/GHSA-j2vp-w788-8fcf",
    "https://nvd.nist.gov/vuln/detail/CVE-2026-105128",
    "https://github.com/laradashboard/laradashboard/pull/341",
    "https://github.com/laradashboard/laradashboard/commit/c08da68236267afc0c0073598f66fadbc1b53b66",
    "https://github.com/laradashboard/laradashboard",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L142",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Controllers/Backend/EmailTemplateController.php#L159",
    "https://github.com/laradashboard/laradashboard/blob/v1.4.2/resources/js/lara-builder/core/LaraBuilder.jsx#L762",
    "https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8",
    "https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-open-redirect-via-email-template-builder-redirect-url",
    "https://github.com/advisories/GHSA-4h8m-c92p-4pmv"
  ],
  "repository_advisory_url": null,
  "severity": "medium",
  "source_code_location": "",
  "summary": "LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers...",
  "type": "unreviewed",
  "updated_at": "2026-10-04T00:31:07Z",
  "url": "https://api.github.com/advisories/GHSA-4h8m-c92p-4pmv",
  "vulnerabilities": [],
  "withdrawn_at": null
}

Text

LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers... LaraDashboard before 1.4.8 contains an open redirect vulnerability that allows remote attackers to redirect users by supplying an unvalidated redirect_url parameter to EmailTemplateController builder and builderEdit. Attackers can send crafted builder links to logged-in users with email template permissions so saving a template navigates them to attacker-controlled phishing sites.