VYPR
Moderate severityNVD Advisory· Published Feb 19, 2024· Updated Mar 25, 2025

CVE-2024-26318

CVE-2024-26318

Description

Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Serenity.Net.CoreNuGet
< 6.8.06.8.0
@serenity-is/corelibnpm
< 6.8.06.8.0

Affected products

3

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.