{"id":"GHSA-cgrj-xjm7-9q27","summary":"Open redirect in web2py","details":"Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.","aliases":["CVE-2022-33146","PYSEC-2026-1060"],"modified":"2026-07-07T11:56:17.166118059Z","published":"2022-06-28T00:01:02Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-05T22:06:03Z","nvd_published_at":"2022-06-27T01:15:00Z","cwe_ids":["CWE-601"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33146"},{"type":"WEB","url":"https://github.com/web2py/web2py/commit/a181b855a43cb8b479d276b082cfcde385768451"},{"type":"WEB","url":"https://github.com/web2py/web2py/commit/d9805606f88f00c0be56438247605cefde73e14e#diff-c1d01f37ee54d813815718760b9c4d7b274e2be7ad18f65552cd564336ab593bR110"},{"type":"PACKAGE","url":"https://github.com/web2py/web2py"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN02158640/index.html"},{"type":"WEB","url":"http://web2py.com"}],"affected":[{"package":{"name":"web2py","ecosystem":"PyPI","purl":"pkg:pypi/web2py"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.22.5"}]}],"versions":["1.96.4","1.98.2","2.1.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-cgrj-xjm7-9q27/GHSA-cgrj-xjm7-9q27.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}