Description
urijs prior to version 1.19.10 is vulnerable to open redirect. This is the result of a bypass for the fix to CVE-2022-0613.
Recommendation
Update the urijs package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.19.10
- Patched version(s): 1.19.10
References
Related Issues
- URL Confusion When Scheme Not Supplied in medialize/uri.js - CVE-2022-1233
- @workos/authkit-session has an Open Redirect via state-derived redirect target - CVE-2026-42565
- Qwik City Open Redirect via fixTrailingSlash - CVE-2026-25149
- Waku has an Open Redirect via `unstable_redirect` Helper - CVE-2026-49456
You might also like:
- Tags:
- npm
- urijs
Anything's wrong? Let us know Last updated on February 03, 2023


