{"id":"CVE-2021-4260","aliases":["GHSA-v279-v2xm-whq9"],"url":"https://o3.security/vulnerability/CVE-2021-4260","summary":"Oils JS vulnerable to Open Redirect","details":"A vulnerability was found in oils-js. It has been declared as critical. This vulnerability affects unknown code of the file core/Web.js. The manipulation leads to open redirect. The attack can be initiated remotely. The name of the patch is fad8fbae824a7d367dacb90d56cb02c5cb999d42. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216268.","published":"2022-12-19T14:15:10.600Z","modified":"2026-07-08T06:00:30.414273978Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"oils","fixedVersion":"8.0.0"}],"fix":{"url":"https://github.com/mannyvergel/oils-js/commit/fad8fbae824a7d367dacb90d56cb02c5cb999d42","label":"mannyvergel/oils-js@fad8fba"},"references":[{"type":"ADVISORY","url":"https://vuldb.com/?id.216268"},{"type":"FIX","url":"https://github.com/mannyvergel/oils-js/commit/fad8fbae824a7d367dacb90d56cb02c5cb999d42"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:00:30.414273978Z"}}