CVE-2026-73084 - Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint
Brief
CVE ID : CVE-2026-73084
Published : Aug. 11, 2026, 4:35 p. m.
- 29 minutes ago
Description : Activepieces is an open source AI workflow automation platform. Prior to 0.
- 0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping.
A crafted request to /api/redirect with a malicious code value can break out of the script context and execute arbitrary JavaScript in the Activepieces origin when a logged-in user opens it. An unauthenticated attacker can access the victim's session tokens or make authenticated API calls on the victim's behalf. This issue is fixed in version 0.
- 0.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
