A vulnerability categorized as problematic has been discovered in Decidim up to 0.30.8/0.31.4/0.31.x. This affects the function Decidim::DownloadYourDataController#download_file of the component Download Your Data. Executing a manipulation can lead to open redirect.

This vulnerability is tracked as CVE-2026-45377. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.