Skip to main content
Loading…
    CVE-2025-61536 — FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted `req.headers.host` header and forces the `http://` scheme. An attacker who can control the `Host` hea — CVE Database · The Intelligence Room