CVE-2026-25477 | toeverything AFFiNE up to 0.25.x Regular Expression /redirect-proxy (EUVD-2026-9258)
A vulnerability was found in toeverything AFFiNE up to 0.25.x. It has been classified as problematic. Affected is an unknown function of the file /redirect-proxy of the component Regular Expression Handler. The manipulation leads to open redirect.
This vulnerability is traded as CVE-2026-25477. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.