{"id":60576,"date":"2026-06-06T12:15:59","date_gmt":"2026-06-06T12:15:59","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=60576"},"modified":"2026-06-06T12:15:59","modified_gmt":"2026-06-06T12:15:59","slug":"mage-ai-sign-in-flow-indextsx-usemutation-cross-site-scripting","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=60576","title":{"rendered":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai\/frontend\/components\/Sessions\/SignForm\/index.tsx of the component Sign-in Flow. Performing a manipulation of the argument query.redirect_url results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.&#8221;,&#8221;published&#8221;:&#8221;2026-06-06T15:45:07.089Z&#8221;,&#8221;modified&#8221;:&#8221;2026-06-06T15:45:07.089Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;Mage AI Sign-in Flow index.tsx useMutation cross site scripting&#8221;,&#8221;source&#8221;:&#8221;VulDB&#8221;,&#8221;references&#8221;:&#8221;https:\/\/vuldb.com\/vuln\/369016\\nhttps:\/\/vuldb.com\/vuln\/369016\/cti\\nhttps:\/\/vuldb.com\/cve\/CVE-2026-11436\\nhttps:\/\/vuldb.com\/submit\/822710\\nhttps:\/\/gist.github.com\/TrebledJ\/8af312cf797391ef7b50b94bb244333a&#8221;,&#8221;id&#8221;:&#8221;CVE-2026-11436&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-79&#8243;,&#8221;CWE-94&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;n\/a Mage AI 0.9.0\\nn\/a Mage AI 0.9.1\\nn\/a Mage AI 0.9.2\\nn\/a Mage AI 0.9.3\\nn\/a Mage AI 0.9.4\\nn\/a Mage AI 0.9.5\\nn\/a Mage AI 0.9.6\\nn\/a Mage AI 0.9.7\\nn\/a Mage AI 0.9.8\\nn\/a Mage AI 0.9.9\\nn\/a Mage AI 0.9.10\\nn\/a Mage AI 0.9.11\\nn\/a Mage AI 0.9.12\\nn\/a Mage AI 0.9.13\\nn\/a Mage AI 0.9.14\\nn\/a Mage AI 0.9.15\\nn\/a Mage AI 0.9.16\\nn\/a Mage AI 0.9.17\\nn\/a Mage AI 0.9.18\\nn\/a Mage AI 0.9.19\\nn\/a Mage AI 0.9.20\\nn\/a Mage AI 0.9.21\\nn\/a Mage AI 0.9.22\\nn\/a Mage AI 0.9.23\\nn\/a Mage AI 0.9.24\\nn\/a Mage AI 0.9.25\\nn\/a Mage AI 0.9.26\\nn\/a Mage AI 0.9.27\\nn\/a Mage AI 0.9.28\\nn\/a Mage AI 0.9.29\\nn\/a Mage AI 0.9.30\\nn\/a Mage AI 0.9.31\\nn\/a Mage AI 0.9.32\\nn\/a Mage AI 0.9.33\\nn\/a Mage AI 0.9.34\\nn\/a Mage AI 0.9.35\\nn\/a Mage AI 0.9.36\\nn\/a Mage AI 0.9.37\\nn\/a Mage AI 0.9.38\\nn\/a Mage AI 0.9.39\\nn\/a Mage AI 0.9.40\\nn\/a Mage AI 0.9.41\\nn\/a Mage AI 0.9.42\\nn\/a Mage AI 0.9.43\\nn\/a Mage AI 0.9.44\\nn\/a Mage AI 0.9.45\\nn\/a Mage AI 0.9.46\\nn\/a Mage AI 0.9.47\\nn\/a Mage AI 0.9.48\\nn\/a Mage AI 0.9.49\\nn\/a Mage AI 0.9.50\\nn\/a Mage AI 0.9.51\\nn\/a Mage AI 0.9.52\\nn\/a Mage AI 0.9.53\\nn\/a Mage AI 0.9.54\\nn\/a Mage AI 0.9.55\\nn\/a Mage AI 0.9.56\\nn\/a Mage AI 0.9.57\\nn\/a Mage AI 0.9.58\\nn\/a Mage AI 0.9.59\\nn\/a Mage AI 0.9.60\\nn\/a Mage AI 0.9.61\\nn\/a Mage AI 0.9.62\\nn\/a Mage AI 0.9.63\\nn\/a Mage AI 0.9.64\\nn\/a Mage AI 0.9.65\\nn\/a Mage AI 0.9.66\\nn\/a Mage AI 0.9.67\\nn\/a Mage AI 0.9.68\\nn\/a Mage AI 0.9.69\\nn\/a Mage AI 0.9.70\\nn\/a Mage AI 0.9.71\\nn\/a Mage AI 0.9.72\\nn\/a Mage AI 0.9.73\\nn\/a Mage AI 0.9.74\\nn\/a Mage AI 0.9.75\\nn\/a Mage AI 0.9.76\\nn\/a Mage AI 0.9.77\\nn\/a Mage AI 0.9.78\\nn\/a Mage AI 0.9.79&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:5.3,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:4.0\/AV:N\/AC:L\/AT:N\/PR:N\/UI:P\/VC:N\/VI:L\/VA:N\/SC:N\/SI:N\/SA:N\/E:P&#8221;,&#8221;version&#8221;:&#8221;4.0&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;Mage AI&#8221;,&#8221;version&#8221;:&#8221;0.9.0&#8243;,&#8221;vendor&#8221;:&#8221;n\/a&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai\/frontend\/components\/Sessions\/SignForm\/index.tsx of the component Sign-in Flow. Performing&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[6,8,22,12,21,13,7,11,5],"class_list":["post-60576","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-cve","tag-cvss","tag-cvss-53","tag-exploit","tag-medium","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=60576\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai\/frontend\/components\/Sessions\/SignForm\/index.tsx of the component Sign-in Flow. Performing...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=60576\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-06T12:15:59+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436\",\"datePublished\":\"2026-06-06T12:15:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576\"},\"wordCount\":560,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-5.3\",\"exploit\",\"MEDIUM\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=60576#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576\",\"name\":\"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-06-06T12:15:59+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=60576\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=60576#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=60576","og_locale":"en_US","og_type":"article","og_title":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai\/frontend\/components\/Sessions\/SignForm\/index.tsx of the component Sign-in Flow. Performing...","og_url":"https:\/\/zero.redgem.net\/?p=60576","og_site_name":"zero redgem","article_published_time":"2026-06-06T12:15:59+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=60576#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=60576"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436","datePublished":"2026-06-06T12:15:59+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=60576"},"wordCount":560,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-5.3","exploit","MEDIUM","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=60576#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=60576","url":"https:\/\/zero.redgem.net\/?p=60576","name":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-06-06T12:15:59+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=60576#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=60576"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=60576#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Mage AI Sign-in Flow index.tsx useMutation cross site scripting_CVE-2026-11436"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/60576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=60576"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/60576\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=60576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=60576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=60576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}