top of page
perceptive_background_267k.jpg

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This …

Published:

1 maart 2026 om 23:00:00

Alert date:

2 maart 2026 om 20:01:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

AFFiNE, an open-source workspace application, contains a critical one-click remote code execution vulnerability in versions prior to 0.25.4. The vulnerability can be exploited through specially crafted affine: URLs embedded on websites. Attackers can trigger the vulnerability through malicious websites with automatic redirects or by embedding crafted links in legitimate websites. When victims interact with these URLs, the browser invokes AFFiNE's custom URL handler, launching the application and processing the malicious URL, resulting in arbitrary code execution without further user interaction. The vulnerability has been patched in version 0.25.4.

Technical details

Mitigation steps:

Affected products:

AFFiNE

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page