Intel

AIKIDO-2026-360647

drupal/cas_server is vulnerable to Open Redirect

Open RedirectCVE-2026-87937 Published 2 days ago

50

Medium Risk

This Affects:

PHPdrupal/cas_server
0.0.1 - 2.0.3
Fixed in 2.0.4
2.1.0 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

A security vulnerability in the Drupal CAS Server module allows attackers to redirect users to an arbitrary external URL during logout. Exploitation requires the attacker to trick a user into clicking a specially crafted link. The vulnerability does not allow authentication bypass or direct compromise of the CAS server.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

drupal/cas_server is vulnerable to Open Redirect in versions 0.0.1 - 2.0.3 and 2.1.0 - 2.1.2.

How to fix this

Upgrade the drupal/cas_server library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform