PT-2025-10631 · Passbolt · Passbolt Api
David Silva
·
Published
2025-03-10
·
Updated
2025-03-11
·
CVE-2025-27913
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Passbolt API versions prior to 5
Description
The issue arises when the server is misconfigured, specifically with an incorrect installation process and disregard of Health Check results. In such cases, the Passbolt API can send email messages with a domain name taken from an attacker-controlled HTTP Host header.
Recommendations
For versions prior to 5, ensure proper server configuration, following the correct installation process and adhering to Health Check results to prevent exploitation. As a temporary workaround, consider restricting access to the email functionality until the issue is resolved.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Passbolt Api