MEDIUM6.1
PYSEC-2026-919
Netflix Security Monkey Open Redirect vulnerability
Quick fix
PYSEC-2026-919 — security-monkey: upgrade to the fixed version with the command below.
pip install --upgrade 'security-monkey>=0.8.0'Details
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/security-monkey
Introduced in:
0Fixed in: 0.8.0Fix
pip install --upgrade 'security-monkey>=0.8.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2017-7266[ADVISORY]
- https://github.com/Netflix/security_monkey/pull/482[WEB]
- https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466[WEB]
- https://github.com/Netflix/security_monkey[PACKAGE]
- https://github.com/Netflix/security_monkey/releases/tag/v0.8.0[WEB]
- https://web.archive.org/web/20201220170714/http://www.securityfocus.com/bid/97088[WEB]
- https://pypi.org/project/security-monkey[PACKAGE]
- https://github.com/advisories/GHSA-j6jq-3q8p-xgg6[ADVISORY]