PatchSiren

getredash CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM getredash CVE published 2026-07-15

CVE-2026-33213

The CVE record for CVE-2026-33213 was published on 2026-07-15T15:16:31.530Z. The vulnerability affects Redash, a package for data visualization and sharing. The get_next_path() function in Redash's authentication module did not normalize multiple leading slashes, allowing a crafted login URL to redirect users to an external attacker-controlled site after authentication. This issue existed from version 5.0 [truncated]