CVE-2025-27913: Passbolt API

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can send email messages with a domain name taken from an attacker-controlled HTTP Host header.

Affected products

  • Passbolt Passbolt API: before 5.0.0 (fixed in 5.0.0)

Published 2025-03-10. Last modified 2026-06-17.