Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin value from the request headers as the email link baseUrl without validation. If an attacker controls the Origin, password reset / email verification links in emails can be generated pointing to the attacker’s domain, causing authentication tokens to be exposed and potentially leading to account takeover. This vulnerability is fixed in 1.93.
References
| Link | Resource |
|---|---|
| https://github.com/appsmithorg/appsmith/commit/6f9ee6226bac13fb4b836940b557913fff78b633 | Patch |
| https://github.com/appsmithorg/appsmith/security/advisories/GHSA-7hf5-mc28-xmcv | Exploit Vendor Advisory |
| https://github.com/appsmithorg/appsmith/security/advisories/GHSA-7hf5-mc28-xmcv | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-01-12 22:16
Updated : 2026-01-21 19:14
NVD link : CVE-2026-22794
Mitre link : CVE-2026-22794
CVE.ORG link : CVE-2026-22794
JSON object : View
Products Affected
appsmith
- appsmith
CWE
CWE-346
Origin Validation Error
