๐Ÿ” CVE Alert

CVE-2026-73084

MEDIUM 6.1

Activepieces: Reflected Cross-Site Scripting in OAuth Redirect Endpoint

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can break out of the script context and execute arbitrary JavaScript in the Activepieces origin when a logged-in user opens it. An unauthenticated attacker can access the victim's session tokens or make authenticated API calls on the victim's behalf. This issue is fixed in version 0.83.0.

CWE CWE-79 CWE-94
Vendor activepieces
Product activepieces
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for activepieces activepieces

Be the first to know when new medium vulnerabilities affecting activepieces activepieces are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

activepieces / activepieces
< 0.83.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/activepieces/activepieces/security/advisories/GHSA-hc39-cm5m-q8g7 github.com: https://github.com/activepieces/activepieces/commit/8be4c8d5e6a79ccbaa74815027432a3c8c311385 github.com: https://github.com/activepieces/activepieces/releases/tag/0.83.0