Affine is a productivity and collaboration platform whose vulnerability footprint concentrates on its core product and centers on application-layer input-handling issues, specifically code injection and open redirect flaws. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Affine over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21853HIGH AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.25.4, there is a one-click remote code execution vulnerability. This vulnerability can be | Mar 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-25477MEDIUM AFFiNE is an open-source, all-in-one workspace and an operating system. Prior to version 0.26.0, there is an Open Redirect vulnerability located at the /redirect-proxy endpoint. Th | Mar 2, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Affine.
Media articles that mention a CVE ID that affects a product developed by Affine — matched by CVE ID, not by vendor name.