Intel

AIKIDO-2026-10203

django-allauth is vulnerable to Open Redirect

Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

51

Medium Risk

This Affects:

PYTHONdjango-allauth
0.58.0 - 65.14.0
Fixed in 65.14.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to open redirect when SAML IdP-initiated single sign-on is enabled (default disabled). The application uses the RelayState parameter without proper validation, allowing an attacker to supply a crafted URL that redirects authenticated users to an external, attacker-controlled site after login.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and SAML IdP-initiated single sign-on is enabled.

Background info

django-allauth is vulnerable to Open Redirect in versions 0.58.0 - 65.14.0.

How to fix this

Upgrade the django-allauth library to the patch version.