CVE-2025-27913
Last modified
CVE-2025-27913 is a low-severity vulnerability rated 2.1/10 on the CVSS scale. Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Passbolt | Passbolt Api | < 5.0.0 |
References
- https://www.passbolt.com/incidents/host-header-injectionMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-27913?
How severe is CVE-2025-27913?
How do I fix CVE-2025-27913?
Are you affected by CVE-2025-27913?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
