


Perceptive Security
SOC/SIEM Consultancy

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This …
Published:
1 March 2026 at 23:00:00
Alert date:
2 March 2026 at 20:01:01
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
AFFiNE, an open-source workspace application, contains a critical one-click remote code execution vulnerability in versions prior to 0.25.4. The vulnerability can be exploited through specially crafted affine: URLs embedded on websites. Attackers can trigger the vulnerability through malicious websites with automatic redirects or by embedding crafted links in legitimate websites. When victims interact with these URLs, the browser invokes AFFiNE's custom URL handler, launching the application and processing the malicious URL, resulting in arbitrary code execution without further user interaction. The vulnerability has been patched in version 0.25.4.
Technical details
Mitigation steps:
Affected products:
AFFiNE
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-21853
https://github.com/toeverything/AFFiNE/commit/c9a4129a3e9376b688c18e1dcd6c87a775caac80
https://github.com/toeverything/AFFiNE/pull/13864
https://github.com/toeverything/AFFiNE/security/advisories/GHSA-67vm-2mcj-8965
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
