CVE-2026-21853 | toeverything AFFiNE up to 0.25.3 URL code injection (GHSA-67vm-2mcj-8965 / EUVD-2026-9252)
A vulnerability described as critical has been identified in toeverything AFFiNE up to 0.25.3. Affected by this vulnerability is an unknown functionality of the component URL Handler. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2026-21853. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.