PT-2025-42474 · Unknown · Felixriddle Dev-Jobs-Handlebars

Published

2025-10-16

·

Updated

2025-10-16

·

CVE-2025-61536

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions FelixRiddle dev-jobs-handlebars version 1.0
Description The software uses absolute password-reset links that rely on the untrusted req.headers.host header and enforces the http:// scheme. This allows an attacker who can control the Host header, or exploit a misconfigured proxy or load balancer, to manipulate the reset links to point to attacker-controlled domains or be delivered via insecure HTTP. This can lead to token theft, phishing, and account takeover. The vulnerable parameter is req.headers.host.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61536

Affected Products

Felixriddle Dev-Jobs-Handlebars