CVE-2017-1000442: Passbolt API

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

Affected products

  • Passbolt Passbolt API: up to and including 1.6.4

Published 2018-01-02. Last modified 2026-06-17.