router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth Endpoint. Executing a manipulation of the argument returnURL can lead to cross site scripting.The identification of this vulnerability is CVE-2026-12811. The attack may be launched remotely. Furthermore, there is an exploit available.
It is advisable to upgrade the affected component.
The researcher explains: "The issue was fixed in v0.8.39 without notifying the wider user base via a security disclosure."
SOCIAL SHARE CARD GENERATOR