Nixpkgs security tracker

Login with GitHub

Details of issue NIXPKGS-2026-0500

NIXPKGS-2026-0500
published 3 months, 3 weeks ago
updated 3 months, 3 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    10 packages
    • python312Packages.affine
    • python313Packages.affine
    • python314Packages.affine
    • python312Packages.affinegap
    • python313Packages.affinegap
    • python314Packages.affinegap
    • python312Packages.affine-gaps
    • python313Packages.affine-gaps
    • haskellPackages.affinely-extended
    • haskellPackages.simple-affine-space
  • @LeSuisse accepted
  • @LeSuisse published on GitHub
AFFiNE: Open Redirect via Regex Bypass in redirect-proxy

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. The flaw exists in the domain validation logic, where an improperly anchored Regular Expression allows an attacker to bypass the whitelist by using malicious domains that end with a trusted string. This issue has been patched in version 0.26.0.

Affected products

AFFiNE
  • ==< 0.26.0

Matching in nixpkgs

pkgs.affine

Workspace with fully merged docs, whiteboards and databases

pkgs.affine-bin

Workspace with fully merged docs, whiteboards and databases

Ignored packages (10)

Package maintainers

Upstream advisory: https://github.com/toeverything/AFFiNE/security/advisories/GHSA-wx9m-v7wq-g289