PT-2026-43372 · Tenable · Tenable
Trebledj
·
Published
2026-05-26
·
Updated
2026-05-26
·
CVE-2026-9566
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
teableio teable versions prior to release.2026-04-21T08-57-20Z.1513
Description
Cross site scripting can be triggered remotely through the manipulation of the
redirect argument within the Sign-up component of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx. The issue occurs because the login redirect flow failed to properly validate the redirect path, allowing the execution of javascript:, data:, and cross-origin redirects.Recommendations
Upgrade to version release.2026-04-21T08-57-20Z.1513.
As a temporary workaround, restrict or validate the
redirect parameter used during the login process to prevent the use of javascript:, data:, or cross-origin URIs.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tenable