CVE-2026-12863
Received Received - Intake
Unvalidated Redirect in Venueless Social Login

Publication date: 2026-06-22

Last updated on: 2026-06-22

Assigner: rami.io

Description
An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-22
Last Modified
2026-06-22
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
venueless venueless to d27864a7 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-12863 is a moderate severity vulnerability affecting the Venueless software. It involves an unvalidated redirect in the social login functionality. This means that the software does not properly verify the destination URL during the login process, which can be exploited by attackers.

An attacker could use this flaw to perform phishing attacks by redirecting users to malicious sites while appearing to use trusted domains.

Impact Analysis

This vulnerability can impact you by enabling phishing attacks through trusted domains, potentially tricking users into visiting malicious websites.

It affects the integrity of the vulnerable system and could also impact the integrity of subsequent systems that interact with it.

The attack requires no privileges and only passive user interaction, making it easier for attackers to exploit.

Mitigation Strategies

To mitigate the CVE-2026-12863 vulnerability, ensure that your Venueless software is updated to a version including or after commit d27864a7, where the unvalidated redirect issue in the social login functionality has been fixed.

This update prevents exploitation of the vulnerability that could be used for phishing attacks leveraging trusted domains.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12863. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart