{"id":"CVE-2026-52097","title":"An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components","summary":"An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"adp","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-10T17:47:30.434700Z"},"published":"2026-09-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:47:57.526Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-52097","references":[{"url":"https://github.com/AppFlowy-IO/AppFlowy"},{"url":"https://github.com/AppFlowy-IO/AppFlowy/blob/main/frontend/appflowy_flutter/lib/core/helpers/url_launcher.dart"},{"url":"https://github.com/AppFlowy-IO/AppFlowy/blob/main/frontend/appflowy_flutter/lib/core/helpers/common_patterns.dart"}],"tags":["cve.org"],"epss":0.00411,"epssPercentile":0.35027,"ingestedAt":"2026-09-11T14:42:19.865Z","slug":"CVE-2026-52097","body":"## Overview\n\nAn issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":52139,"id":"CVE-2026-52097","ts":1789063373219,"field":"cvss","old":null,"new":"6.8"},{"seq":52138,"id":"CVE-2026-52097","ts":1789063373219,"field":"severity","old":"none","new":"medium"}]}