CWE-1022: Use of Web Link to Untrusted Target with window.opener Access
The web application produces links to untrusted external sites outside of its sphere of control, but it does not properly prevent the external site from modifying security-critical properties of the window.opener object, such as the location property.
13 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-39727 — IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing
- CVE-2025-33014 — IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
- CVE-2025-42941 — Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
- CVE-2026-71555 — PILOS: Reverse tabnabbing in room description
- CVE-2025-59842 — JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
Recently published
- CVE-2026-71555 — PILOS: Reverse tabnabbing in room description
- CVE-2025-59842 — JupyterLab LaTeX typesetter links did not enforce `noopener` attribute
- CVE-2025-42941 — Reverse Tabnabbing vulnerability in SAP Fiori (Launchpad)
- CVE-2025-33014 — IBM Sterling B2B Integrator and IBM Sterling File Gateway link injection
- CVE-2024-39727 — IBM Engineering Lifecycle Optimization - Engineering Insights tabnabbing