CVE-2026-41513 PUBLISHED

Horilla: Open Redirect via Unvalidated `next` Parameter in Notification Endpoints

Assigner: GitHub_M
Reserved: 20.04.2026 Published: 12.05.2026 Updated: 12.05.2026

Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor horilla
Product horilla-hr
Versions
  • Version <= 1.5.0 is affected

References

Problem Types

  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') CWE