PT-2025-10631 · Passbolt · Passbolt Api

David Silva

·

Published

2025-03-10

·

Updated

2025-03-11

·

CVE-2025-27913

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Passbolt API versions prior to 5
Description The issue arises when the server is misconfigured, specifically with an incorrect installation process and disregard of Health Check results. In such cases, the Passbolt API can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
Recommendations For versions prior to 5, ensure proper server configuration, following the correct installation process and adhering to Health Check results to prevent exploitation. As a temporary workaround, consider restricting access to the email functionality until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27913

Affected Products

Passbolt Api