A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The manipulation of the argument redirect_uri results in open redirect. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 24 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/system/service/oauth2/OAuth2ClientServiceImpl.java of the component OAuth2 Client. The manipulation of the argument redirect_uri results in open redirect. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title YunaiV/zhijiantianya ruoyi-vue-pro OAuth2 Client OAuth2ClientServiceImpl.java validOAuthClientFromCache redirect
First Time appeared Yunaiv
Yunaiv ruoyi-vue-pro
Zhijiantianya
Zhijiantianya ruoyi-vue-pro
Weaknesses CWE-601
CPEs cpe:2.3:a:yunaiv:ruoyi-vue-pro:*:*:*:*:*:*:*:*
cpe:2.3:a:zhijiantianya:ruoyi-vue-pro:*:*:*:*:*:*:*:*
Vendors & Products Yunaiv
Yunaiv ruoyi-vue-pro
Zhijiantianya
Zhijiantianya ruoyi-vue-pro
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-24T19:30:09.743Z

Reserved: 2026-09-24T11:34:25.729Z

Link: CVE-2026-97325

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T20:17:35.730

Modified: 2026-09-24T20:17:35.730

Link: CVE-2026-97325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses