FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-620 | |
Metrics |
cvssV3_1
|
Thu, 16 Oct 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-16T15:31:59.365Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61536

Updated: 2025-10-16T15:31:54.603Z

Status : Awaiting Analysis
Published: 2025-10-16T15:15:34.317
Modified: 2025-10-16T16:15:38.920
Link: CVE-2025-61536

No data.

No data.