Executive brief
Blitz, a full-stack web framework, contains a security flaw in its default sign-in components. An attacker can create a malicious link that, when clicked by a user, executes unauthorized code in the user's browser after they log in. This could allow an attacker to steal sensitive session information, perform actions as the user, or display fraudulent login prompts to steal credentials.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Blitz's sign-in templates (specifically LoginForm.tsx and login.tsx). The vulnerability stems from the application's handling of the 'next' query parameter, which determines where a user is redirected after a successful login. The code takes the 'next' value directly from the URL and passes it to 'router.push()'. Because 'router.push' in the underlying Next.js framework can resolve to 'window.location', it accepts and executes 'javascript:' URIs. An attacker can exploit this by crafting a URL such as '/auth/login?next=javascript:alert(1)'. Successful exploitation requires the victim to click the link and complete a login, at which point the payload executes in the context of the application's origin. As of the advisory date, no official patch has been released by the vendor.
Affected products
- blitz-js blitz <= 3.0.2
Timeline
- 2026-03-08: disclosed: Vulnerability discovered and reported to maintainers.
- 2026-05-26: advisory: Public disclosure via GitHub Advisory Database and NVD.