{"id":"PYSEC-2026-1060","summary":"Open redirect in web2py","details":"Open redirect vulnerability in web2py versions prior to 2.22.5 allows a remote attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.","aliases":["CVE-2022-33146","GHSA-cgrj-xjm7-9q27"],"modified":"2026-07-07T11:45:31.006040124Z","published":"2026-07-06T08:03:30.915282Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33146"},{"type":"WEB","url":"https://github.com/web2py/web2py/commit/a181b855a43cb8b479d276b082cfcde385768451"},{"type":"WEB","url":"https://github.com/web2py/web2py/commit/d9805606f88f00c0be56438247605cefde73e14e#diff-c1d01f37ee54d813815718760b9c4d7b274e2be7ad18f65552cd564336ab593bR110"},{"type":"PACKAGE","url":"https://github.com/web2py/web2py"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN02158640/index.html"},{"type":"WEB","url":"http://web2py.com"},{"type":"PACKAGE","url":"https://pypi.org/project/web2py"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-cgrj-xjm7-9q27"}],"affected":[{"package":{"name":"web2py","ecosystem":"PyPI","purl":"pkg:pypi/web2py"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.22.5"}]}],"versions":["1.96.4","1.98.2","2.1.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/web2py/PYSEC-2026-1060.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}