CVE-2026-51564

Medium severity, CVSS 4.9. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.

Published 2026-07-27. Last modified 2026-07-28.