{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "versions": [
              {
                "introduced": "4.119.0"
              },
              {
                "fixed": "4.233.0"
              }
            ]
          },
          "events": [
            {
              "introduced": "bfc84be6903b8dedb5b1de9df76159b8910c00fa"
            },
            {
              "fixed": "86068f42d4a4bc07afd40e0b11664ac6d261cca0"
            },
            {
              "fixed": "5bcfdbe066e8c899f3ecf3fdcdbacc2ecba7f02f"
            }
          ],
          "repo": "https://github.com/habitrpg/habitica",
          "type": "GIT"
        }
      ]
    }
  ],
  "details": "In habitica versions v4.119.0 through v4.232.2 are vulnerable to open redirect via the login page.",
  "id": "CVE-2022-23078",
  "modified": "2026-03-13T21:54:18.339883719Z",
  "published": "2022-06-22T12:15:08.067Z",
  "references": [
    {
      "type": "FIX",
      "url": "https://github.com/HabitRPG/habitica/commit/5bcfdbe066e8c899f3ecf3fdcdbacc2ecba7f02f"
    },
    {
      "type": "EVIDENCE",
      "url": "https://www.mend.io/vulnerability-database/CVE-2022-23078"
    }
  ]
}