DiracX-Web is vulnerable to attack through an Open Redirect on its login page
- Severity:
- Medium
Description
An attacker can forge a request to redirect an authenticated user to any arbitrary website.
Recommendation
Update the @dirac-grid/diracx-web-components package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.0-a8
- Patched version(s): 0.1.0-a8
References
Related Issues
- Axios is vulnerable to DoS attack through lack of data size check - CVE-2025-58754
- @pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation - CVE-2025-53626
- Flowise is vulnerable to arbitrary file write through its WriteFileTool - CVE-2025-61913
- Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - materialize-css - CVE-2019-11004
You might also like:
- Tags:
- npm
- @dirac-grid/diracx-web-components
Anything's wrong? Let us know Last updated on July 17, 2025


