CVE-2026-25477 - AFFiNE: Open Redirect via Regex Bypass in redirect-proxy

CVE-2026-25477 - AFFiNE: Open Redirect via Regex Bypass in redirect-proxy

CVE ID : CVE-2026-25477 Published : March 2, 2026, 8:16 p.m. | 1 hour, 33 minutes ago Description : AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0. Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 2, 2026