VYPR
Unrated severityNVD Advisory· Published Jan 11, 2024· Updated Jun 17, 2025

XSS in Authentik via JavaScript-URI as Redirect URI and form_post Response Mode

CVE-2024-21637

Description

Authentik is an open-source Identity Provider. Authentik is a vulnerable to a reflected Cross-Site Scripting vulnerability via JavaScript-URIs in OpenID Connect flows with response_mode=form_post. This relatively user could use the described attacks to perform a privilege escalation. This vulnerability has been patched in versions 2023.10.6 and 2023.8.6.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.