CVE-2026-25477

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:affine:affine:*:*:*:*:-:*:*:*

History

10 Apr 2026, 14:28

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:affine:affine:*:*:*:*:-:*:*:*
References () https://github.com/toeverything/AFFiNE/security/advisories/GHSA-wx9m-v7wq-g289 - () https://github.com/toeverything/AFFiNE/security/advisories/GHSA-wx9m-v7wq-g289 - Third Party Advisory
Summary
  • (es) AFFiNE es un espacio de trabajo todo en uno de código abierto y un sistema operativo. Antes de la versión 0.26.0, existe una vulnerabilidad de redirección abierta ubicada en el endpoint /redirect-proxy. El fallo reside en la lógica de validación de dominio, donde una expresión regular anclada incorrectamente permite a un atacante eludir la lista blanca utilizando dominios maliciosos que terminan con una cadena de confianza. Este problema ha sido parcheado en la versión 0.26.0.
First Time Affine
Affine affine

02 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 20:16

Updated : 2026-06-17 10:24


NVD link : CVE-2026-25477

Mitre link : CVE-2026-25477

CVE.ORG link : CVE-2026-25477


JSON object : View

Products Affected

affine

  • affine
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')