Avo has a XSS vulnerability on `return_to` param
Published: March 18, 2026
SECURITY IDENTIFIERS
- CVE: CVE-2026-33209 (NVD)
- GHSA: GHSA-762r-27w2-q22j
- Vendor Advisory: https://github.com/avo-hq/avo/security/advisories/GHSA-762r-27w2-q22j
GEM
PATCHED VERSIONS
>= 3.30.3
DESCRIPTION
Description
A reflected cross-site scripting (XSS) vulnerability exists in
the return_to query parameter used in the avo interface.
An attacker can craft a malicious URL that injects arbitrary JavaScript, which is executed when he clicks a dynamically generated navigation button.
Impact
This vulnerability may allow execution of arbitrary JavaScript in the context of the application.
Impact varies depending on deployment:
- In unauthenticated setups: exploitable via crafted links sent to users.
- In authenticated setups: limited to authenticated users and requires interaction.
