PT-2026-28487 · Ory+1 · Ory Polis+1

CVE-2026-33506

·

Publicado

2026-03-26

·

Atualizado

2026-03-26

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ory Polis versions prior to 26.2.0
Description Ory Polis, previously known as BoxyHQ Jackson, functions as a bridge or proxy for a SAML login flow to OAuth 2.0 or OpenID Connect. Versions prior to 26.2.0 are susceptible to a DOM-based Cross-Site Scripting (XSS) issue within the login functionality. The application inappropriately trusts a URL parameter, callbackUrl, which is then passed to the router.push function. An attacker can create a malicious link that, when opened by an authenticated user (or an unauthenticated user who subsequently logs in), can trigger a client-side redirection and execute arbitrary JavaScript code within the user's browser. This could potentially lead to credential theft and unauthorized actions performed on behalf of the victim.
Recommendations Versions prior to 26.2.0 should be updated to version 26.2.0 or later.

Exploit

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33506
GHSA-3WJR-6GW8-9J22

Produtos afetados

Boxyhq Jackson
Ory Polis