CVE-2026-52097
Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components
Published 2026-09-10. Last modified 2026-09-10.