PT-2026-25381 · Kasuganosoras+1 · Pigeon
Mabjr33
+1
·
Published
2026-03-13
·
Updated
2026-03-16
·
CVE-2026-32616
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pigeon versions prior to 1.0.201
Description
Pigeon is a message board/notepad/social system/blog. The application uses
$ SERVER['HTTP HOST'] without validation when constructing email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in an HTTP request, causing the verification link sent to a user’s email to point to an attacker-controlled domain. This can lead to account takeover by stealing the email verification token. The vulnerable component uses the $ SERVER['HTTP HOST'] variable to construct the email verification URL.Recommendations
Update Pigeon to version 1.0.201 or later.
Exploit
Fix
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pigeon