CVE-2026-21853Disclosure(affine / affine)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affine affine systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be exploited by embedding a specially crafted affine: URL on a website. An attacker can trigger the vulnerability in two common scenarios: 1/ A victim visits a malicious website controlled by the attacker and the website redirect to the URL automatically, or 2/ A victim clicks on a crafted link embedded on a legitimate website (e.g., in user-generated content). In both cases, the browser invokes AFFiNE custom URL handler, which launches the AFFiNE app and processes the crafted URL. This results in arbitrary code execution on the victim’s machine, without further interaction. This issue has been patched in version 0.25.4.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • affine

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-02); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
affine

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-02: 2Mentions · 2026-03-03: 2Patch / Workaround · 2026-03-02: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-02: 2Technical Details · 2026-03-03: 203-0203-03
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A Remote Code Execution vulnerability (CVE-2026-21853) affects `AFFiNE` desktop via custom URL handling. Update to patch this #RCE flaw. #AppSec https://www.pulsepatch.io/posts/cve-2026-21853-affine-remote-code-execution

    Post summary

    The post announces a CVE-2026-21853 Remote Code Execution flaw in AFFiNE desktop, caused by custom URL handling, and urges users to apply the available patch.

    0000048
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21853 Remote Code Execution in AFFiNE via Maliciously Crafted URL Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21853

    Post summary

    A new CVE (CVE-2026-21853) has been disclosed, indicating a remote code execution vulnerability in AFFiNE via a maliciously crafted URL handler.

    0000055
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-21853: HIGH] Warning: A one-click remote code execution vulnerability in AFFiNE's <v0.25.4 has been patched. Attackers could exploit by embedding a crafted URL triggering code execution on victims'...#cve,CVE-2026-21853,#cybersecurity https://cvefind.com/CVE-2026-21853

    Post summary

    AFFiNE versions below v0.25.4 suffered a one-click RCE vulnerability (CVE-2026-21853) that has now been patched; no PoC, exploit code, or active exploitation is reported.

    0000056
    590 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-21853 - High AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be exploited ... https://www.thehackerwire.com/vulnerability/CVE-2026-21853/ https://t.co/pJRIRriwFE

    Post summary

    AFFiNE versions prior to 0.25.4 contain a high‑severity one‑click remote code execution vulnerability (CVE‑2026‑21853) that can be exploited, but the post provides no PoC, exploit code, or patch details.

    0000046
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaffineaffine---

Explore more