CVE-2025-63784: Onlook

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback/route.ts in Onlook web application 0.2.32. The vulnerability occurs because the application trusts the X-Forwarded-Host header value without proper validation when constructing a redirect URL. A remote attacker can send a manipulated X-Forwarded-Host header to redirect an authenticated user to an arbitrary external website under their control, which can be exploited for phishing attacks.

Affected products

  • Onlook Onlook: version 0.2.32 only

Published 2025-11-07. Last modified 2026-06-17.