Executive brief
Teable, an open-source no-code database platform, is vulnerable to a security flaw in its login and sign-up pages. An attacker can create a malicious link that, if clicked by a user who then logs in, executes unauthorized code in that user's browser. This could allow an attacker to steal sensitive data, hijack user sessions, or perform actions on the user's behalf without their knowledge.
Technical details
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in Teable's sign-in and sign-up functionality within 'apps/nextjs-app/src/features/auth/pages/LoginPage.tsx'. The application improperly handles the 'redirect' query parameter by passing it directly to Next.js 'router.push()' without sanitization. Because 'router.push()' can resolve 'javascript:' URIs to 'window.location', an attacker can execute arbitrary JavaScript in the victim's browser context. Exploitation requires the victim to click a crafted link and complete a fresh login session. Successful exploitation allows for session hijacking and unauthorized API requests. The issue is fixed in version release.2026-04-21T08-57-20Z.1513 by implementing 'isValidRedirectPath()' to block non-http(s) schemes and cross-origin redirects.
Affected products
- teableio Teable up to 1.9.x
Timeline
- 2026-03-07: disclosed: Vulnerability reported to vendor via coordinated disclosure.
- 2026-03-25: patched: Fix merged into develop branch.
- 2026-04-21: advisory: Official release containing the fix published.
- 2026-05-26: other: CVE-2026-9566 published.
References
- https://gist.github.com/TrebledJ/98575dc5aecb47433f02ff942e6aedf1
- https://github.com/Teableio/Teable/
- https://github.com/Teableio/Teable/pull/2827
- https://github.com/teableio/teable/releases/tag/release.2026-04-21T08-57-20Z.1513
- https://vuldb.com/submit/815798
- https://vuldb.com/vuln/365628
- https://vuldb.com/vuln/365628/cti