VYPR
Critical severity9.6OSV Advisory· Published Jan 12, 2026· Updated Jun 17, 2026

CVE-2026-22794

CVE-2026-22794

Description

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Appsmithorg/AppsmithOSV3 versions
    V1.22, v.1.6.23, v.1.6.25, …+ 2 more
    • (no CPE)range: V1.22, v.1.6.23, v.1.6.25, …
    • cpe:2.3:a:appsmith:appsmith:*:*:*:*:*:*:*:*range: <1.93
    • (no CPE)range: <1.93
  • osv-coords
    Range: < 1.93.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.