A reflected cross-site scripting (XSS) vulnerability exists in the return_to query parameter used in the avo interface.
An attacker can craft a malicious URL that injects arbitrary JavaScript, which is executed when he clicks a dynamically generated navigation button.
This vulnerability may allow execution of arbitrary JavaScript in the context of the application.
Impact varies depending on deployment:
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-18T17:26:59Z",
"nvd_published_at": "2026-03-20T23:16:45Z",
"severity": "MODERATE"
}