{"id":"CVE-2021-3647","aliases":["GHSA-89gv-h8wf-cg8r"],"url":"https://o3.security/vulnerability/CVE-2021-3647","summary":"URIjs Vulnerable to Hostname spoofing via backslashes in URL ","details":"URI.js is vulnerable to URL Redirection to Untrusted Site","published":"2021-07-16T11:15:11.383Z","modified":"2026-07-09T05:44:32.371381Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"urijs","fixedVersion":"1.19.7"}],"fix":{"url":"https://github.com/medialize/URI.js/commit/ac43ca8f80c042f0256fb551ea5203863dec4481","label":"medialize/URI.js@ac43ca8"},"references":[{"type":"REPORT","url":"https://huntr.dev/bounties/1625558772840-medialize/URI.js"},{"type":"FIX","url":"https://github.com/medialize/URI.js/commit/ac43ca8f80c042f0256fb551ea5203863dec4481"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T05:44:32.371381Z"}}