Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
6.9
AFFiNE: Malicious Redirects Possible in Older Versions
CVE-2026-25477
Summary
Older versions of AFFiNE's all-in-one workspace and OS may allow attackers to redirect users to malicious websites by exploiting a flaw in domain validation. This could lead to phishing or other attacks. Upgrade to version 0.26.0 or later to fix the issue.
Original title
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in ...
Original description
AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.
nvd CVSS4.0
6.9
Vulnerability type
CWE-601
Open Redirect
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026