Medium severity6.1NVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026
CVE-2026-54724
CVE-2026-54724
Description
Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kiwitcmsPyPI | <= 12.4 | — |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-hmj5-jm8h-h9fhghsaADVISORY
- github.com/kiwitcms/Kiwi/releases/tag/v16.1nvdWEB
- github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fhnvdWEB
- kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161ghsaWEB
- github.com/kiwitcms/Kiwi/commit/93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06nvd
News mentions
0No linked articles in our index yet.