CVE-2026-52097

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

  • Published Sep 10, 2026
  • CVSS 6.8 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2026-52097 at the National Vulnerability Database