CVE-2026-73084Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can break out of the script context and execute arbitrary JavaScript in the Activepieces origin when a logged-in user opens it. An unauthenticated attacker can access the victim's session tokens or make authenticated API calls on the victim's behalf. This issue is fixed in version 0.83.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-11: 3Patch / Workaround · 2026-08-11: 2Technical Details · 2026-08-11: 308-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73084 Cross-Site Scripting in Activepieces OAuth Callback Endpoint Prior to 0.83.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73084

    Post summary

    The entry announces a new XSS vulnerability in Activepieces OAuth callbacks affecting versions before 0.83.0, implying that updating to 0.83.0 removes the flaw.

    00001104
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-73084 Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query paramet… https://www.cve.org/CVERecord?id=CVE-2026-73084 ----- Traducción: CVE-2026-73084 Act… http://infoflow.cloud`

    Post summary

    The post provides basic disclosure details of CVE-2026-73084, highlighting an input‑exposure flaw in Activepieces’ OAuth callback endpoint but does not mention any PoC, exploit, or mitigation.

    0000035
    97 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-73084 Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query paramet… https://www.cve.org/CVERecord?id=CVE-2026-73084

    Post summary

    The CVE affects Activepieces’ OAuth redirect endpoint before version 0.83.0; upgrading to 0.83.0 or later removes the vulnerability.

    000001.3K
    57.9K followersView on X

Explore more