CVE-2026-33506 identifies a DOM-based Cross-Site Scripting (XSS) vulnerability in Ory Polis (formerly BoxyHQ Jackson) versions prior to 26.2.0, specifically within its login functionality due to improper trust of a URL parameter. Rated 8.8 High, this flaw allows an attacker to craft a malicious link that, when opened by a user, performs a client-side redirect and executes arbitrary JavaScript in their browser. This could lead to significant impacts such as credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim. There is currently no evidence of active exploitation, nor publicly available exploit code, though the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 26.2.0CPE matchmatch criteria | cpe:2.3:a:ory:polis:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.