Intel

AIKIDO-2026-10464

@boxyhq/saml-jackson is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2026-33506 Published Apr 9, 2026

88

High Risk

This Affects:

JS@boxyhq/saml-jackson
0.0.1 - 1.52.2
Fixed in 26.2.0
Are you affected? Scan for Free

TL;DR

A DOM-based Cross-Site Scripting (XSS) vulnerability was identified in Ory Polis’s login flow. The application incorrectly trusts the callbackUrl parameter and passes it to router.push, allowing an attacker to craft a malicious link that triggers a client-side redirect and executes arbitrary JavaScript in the victim’s browser. If opened by an authenticated user, or by a user who logs in afterward, this could enable session or credential theft, unauthorized actions in the user’s context, and potential internal network abuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@boxyhq/saml-jackson is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 1.52.2.

How to fix this

Upgrade the @boxyhq/saml-jackson library to the patch version.