VDB
Sign up
MEDIUM6.1

PYSEC-2026-919

Netflix Security Monkey Open Redirect vulnerability

Quick fix

PYSEC-2026-919 — security-monkey: upgrade to the fixed version with the command below.

pip install --upgrade 'security-monkey>=0.8.0'

Details

Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/security-monkey
Introduced in: 0Fixed in: 0.8.0
Fixpip install --upgrade 'security-monkey>=0.8.0'

References