Remote Code Execution Vulnerability in AFFiNE by ToEverything
CVE-2026-21853
8.8HIGH
What is CVE-2026-21853?
Prior to version 0.25.4, AFFiNE, an all-in-one open-source workspace, was vulnerable to a one-click remote code execution exploit. This vulnerability could be leveraged by embedding a malicious affine: URL within a website. Users were at risk in two primary scenarios: first, when they unknowingly visited a malicious site leading them to the crafted URL; second, if they clicked on a misleading link found on a legitimate site. Both actions would trigger the browser to invoke the AFFiNE custom URL handler, potentially resulting in arbitrary code execution on the user's machine without any additional interaction. This critical vulnerability has been addressed in the 0.25.4 release.
Affected Version(s)
AFFiNE < 0.25.4
