CVE-2026-39600
Received Received - Intake

Open Redirect in Aculect AI Companion

Vulnerability report for CVE-2026-39600, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Patchstack

Description

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Mehul Gohil Aculect AI Companion aculect-ai-companion allows Phishing.This issue affects Aculect AI Companion: from n/a through 0.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mehul_gohil aculect_ai_companion From 0.8.1 (inc)
mehul_gohil aculect_ai_companion to 0.8.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an Open Redirect vulnerability in the Aculect AI Companion WordPress plugin. It allows attackers to craft malicious links that redirect users to untrusted sites without validation. The vulnerability exists in versions 0.8.1 and below.

Detection Guidance

Detecting this vulnerability requires checking for unvalidated redirects in the Aculect AI Companion plugin. Inspect network traffic for suspicious URLs that redirect users without validation. Review plugin code for unsanitized user inputs used in redirect functions. Check web server logs for unusual redirect patterns or external domain accesses.

Impact Analysis

Attackers can use this to trick users into visiting phishing sites or malware downloads. Users might unknowingly share sensitive information or install malicious software. The attack requires a privileged user to interact with a malicious link.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by enabling phishing attacks through untrusted redirects. If exploited, it may lead to unauthorized data access or disclosure, violating confidentiality requirements under these regulations.

Mitigation Strategies

Immediately update the Aculect AI Companion plugin to the latest version if available. If no patch exists, disable the plugin until a fix is released. Implement input validation for all user-provided URLs. Monitor network traffic for signs of exploitation. Consider removing the plugin if it is not essential.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39600. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart