In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade local-deep-research to version 1.0.0 or higher.
local-deep-research is an AI-powered research assistant with deep, iterative analysis using LLMs and web searches
Affected versions of this package are vulnerable to Open Redirect via the next_page query parameter in the post-authentication redirection flow. An attacker can exploit this vulnerability by supplying a crafted next_page value to the local_deep_research.web.auth.routes.login handler, causing users to be redirected to an attacker-controlled domain after login, which can facilitate phishing attacks or credential theft.