VYPR
Vendor

Onlook

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2025-63783HigNov 7, 2025
    risk 0.49cvss 7.6epss 0.00

    A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delete, add/remove tag) of the Onlook web application 0.2.32. The vulnerability exists because the API fails to verify the ownership or membership of the currently…

  • CVE-2025-63784MedNov 7, 2025
    risk 0.42cvss 6.5epss 0.00

    An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation…

  • CVE-2025-63785MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2.32. This vulnerability occurs because user-supplied input is not properly sanitized before being directly injected into the DOM via innerHTML when editing a…

  • CVE-2026-65013HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get,…