PatchSiren

Casbin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW Casbin CVE published 2026-04-03

CVE-2026-5467

A low-severity open redirect vulnerability was identified in Casdoor 2.356.0's OAuth Authorization Request Handler. The issue is caused by manipulation of the redirect_uri argument. Remote attacks are possible. The exploit is publicly available. The vendor, Casbin, was contacted but did not respond. This vulnerability has a CVSS score of 2.1 and is considered low severity. It allows remote attackers to la [truncated]