CVE-2026-73084
Last modified
CVE-2026-73084 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a malicious code value can break out of the script context and execute arbitrary JavaScript in the Activepieces origin when a logged-in user opens it. An unauthenticated attacker can access the victim's session tokens or make authenticated API calls on the victim's behalf. This issue is fixed in version 0.83.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| activepieces | activepieces | < 0.83.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-73084?
How severe is CVE-2026-73084?
How do I fix CVE-2026-73084?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73079Sub2API is an AI API gateway platform designed to distribute…8.5
- CVE-2026-7308An authenticated user with upload permission to a hosted rep…5.4
- CVE-2026-73080SeaweedFS is a distributed storage system. Prior to 4.24, Vo…9.3
- CVE-2026-73081Activepieces is an open source AI workflow automation platfo…8.7
- CVE-2026-73082Activepieces is an open source AI workflow automation platfo…5.3
- CVE-2026-73083Activepieces is an open source AI workflow automation platfo…7.6
- CVE-2026-73085Audiobookshelf is a self-hosted audiobook and podcast server…5.3
- CVE-2026-73086nanoid is a secure, URL-friendly, unique string ID generator…7.4
- CVE-2026-73087Dozzle is a realtime log viewer for docker containers. From …2.3
- CVE-2026-73088Browserslist is a configuration tool for sharing target brow…7.5
- CVE-2026-73089Browserslist is a configuration tool for sharing target brow…7.5
- CVE-2026-7309A flaw was found in the OpenShift Container Platform build s…4.3
Are you affected by CVE-2026-73084?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
