{"id":"CVE-2021-33604","aliases":["GHSA-c99r-67x4-whj6"],"url":"https://o3.security/vulnerability/CVE-2021-33604","summary":"Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19","details":"URL encoding error in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.","published":"2021-06-24T12:15:08.157Z","modified":"2026-09-07T08:09:07.088352Z","cvss":{"score":2.5,"severity":"LOW","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.vaadin:vaadin-bom","fixedVersion":"14.6.2"},{"ecosystem":"Maven","name":"com.vaadin:vaadin-bom","fixedVersion":"19.0.9"}],"fix":{"url":"https://github.com/vaadin/flow/pull/11099","label":"vaadin/flow#11099"},"references":[{"type":"ADVISORY","url":"https://vaadin.com/security/cve-2021-33604"},{"type":"FIX","url":"https://github.com/vaadin/flow/pull/11099"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T08:09:07.088352Z"}}