top of page
perceptive_background_267k.jpg

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This …

Published:

1 March 2026 at 23:00:00

Alert date:

2 March 2026 at 20:01:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

AFFiNE, an open-source workspace application, contains a critical one-click remote code execution vulnerability in versions prior to 0.25.4. The vulnerability can be exploited through specially crafted affine: URLs embedded on websites. Attackers can trigger the vulnerability through malicious websites with automatic redirects or by embedding crafted links in legitimate websites. When victims interact with these URLs, the browser invokes AFFiNE's custom URL handler, launching the application and processing the malicious URL, resulting in arbitrary code execution without further user interaction. The vulnerability has been patched in version 0.25.4.

Technical details

Mitigation steps:

Affected products:

AFFiNE

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page