A vulnerability categorized as problematic has been discovered in Decidim up to 0.30.8/0.31.4/0.31.x. This affects the function
Decidim::DownloadYourDataController#download_file of the component Download Your Data. Executing a manipulation can lead to open redirect.
This vulnerability is tracked as CVE-2026-45377. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.