Description
An attacker can forge a request to redirect an authenticated user to any arbitrary website.
Recommendation
Update the @dirac-grid/diracx-web-components package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.0-a8
- Patched version(s): 0.1.0-a8
References
Could your website be exposed too?
SmartScanner can check your website for DiracX-Web is vulnerable to attack through an Open Redirect on its login page and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Axios is vulnerable to DoS attack through lack of data size check - CVE-2025-58754
- @pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation - CVE-2025-53626
- Flowise is vulnerable to arbitrary file write through its WriteFileTool - CVE-2025-61913
- Materialize-css vulnerable to Improper Neutralization of Input During Web Page Generation - materialize-css - CVE-2019-11004
You might also like:
See something that needs correcting? Let us knowUpdated July 17, 2025


