CVE-2026-21853

8.8

ToEverything · AFFiNE

A remote code execution vulnerability in AFFiNE allows attackers to trigger arbitrary code execution via a specially crafted affine: URL protocol handler.

Executive summary

A remote code execution vulnerability in the AFFiNE application, caused by improper handling of custom URL protocols, poses a critical risk to user workstations.

Vulnerability

This is a code injection vulnerability (CWE-94) occurring within the custom URL handler of the AFFiNE application. The flaw allows an unauthenticated remote attacker to achieve arbitrary code execution on a victim's machine when a user clicks a malicious link or is redirected to a crafted affine: URL.

Business impact

Successful exploitation grants an attacker the ability to execute arbitrary code with the privileges of the logged-in user, potentially leading to a full system compromise. With a CVSS score of 8.8, this high-severity vulnerability represents a significant risk to data confidentiality, integrity, and availability within the organization.

Remediation

Immediate Action: Update the AFFiNE application to version 0.25.4 or later immediately to resolve the vulnerable URL handler logic.

Proactive Monitoring: Review endpoint security logs for unusual process execution patterns originating from the AFFiNE application or attempts to trigger custom protocol handlers.

Compensating Controls: Implement browser-based security policies that restrict or warn users before opening custom URL protocols if an update cannot be deployed immediately.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for complete system compromise and the existence of a proof-of-concept, this vulnerability should be prioritized for immediate remediation. Organizations should push the 0.25.4 update to all affected workstations as a matter of urgency to eliminate the attack vector.

Sources