Onlook maintains a focused web-based visual development and editing platform where its disclosures concentrate on application-layer input-handling and output-encoding issues, including cross-site scripting, open redirects, and improper input validation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Onlook over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-63783HIGH A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The | Nov 7, 2025 | 7.6 | 25 | NO | NO |
CVE-2025-63784MEDIUM An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerabilit | Nov 7, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-63785MEDIUM A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input i | Nov 7, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Onlook.
Media articles that mention a CVE ID that affects a product developed by Onlook — matched by CVE ID, not by vendor name.