GHSA-7fmm-xcgh-ggrfMediumCVSS 6.8
An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the...
🔗 CVE IDs covered (1)
📋 Description
An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-52097
- https://github.com/AppFlowy-IO/AppFlowy
- https://github.com/AppFlowy-IO/AppFlowy/blob/main/frontend/appflowy_flutter/lib/core/helpers/common_patterns.dart
- https://github.com/AppFlowy-IO/AppFlowy/blob/main/frontend/appflowy_flutter/lib/core/helpers/url_launcher.dart
- https://github.com/advisories/GHSA-7fmm-xcgh-ggrf