VYPR
Unrated severityNVD Advisory· Published Nov 11, 2021· Updated Apr 30, 2025

Talkyard - Host-Header Injection Leads to Account Takeover

CVE-2021-25980

Description

In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular, are vulnerable to Host Header Injection. By luring a victim application-user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Talkyard versions before a fix are vulnerable to Host Header Injection via the forgot password functionality, enabling account takeover.

Vulnerability

Talkyard, a comment forum software, is vulnerable to Host Header Injection in versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1, and tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular [2]. The vulnerability resides in the forgot password functionality, which fails to validate the Host header, allowing an attacker to manipulate the password reset link [2].

Exploitation

An unauthenticated attacker can exploit this by luring a victim application-user to click on a crafted link that uses a malicious Host header [2]. The link triggers the forgot password flow, and because the server uses the Host header to generate the reset link, the attacker can intercept the reset token and set a new password for the victim's account [2]. No authentication or special network position is required beyond crafting the malicious link and tricking the user into clicking it.

Impact

Successful exploitation allows the attacker to reset the victim's password and gain full control of the affected Talkyard account [2]. This leads to unauthorized access to the user's messages, posts, and administrative functions if the victim has elevated privileges. The impact is considered high as it compromises account integrity and confidentiality.

Mitigation

As of the available references, no specific fix version has been disclosed. The commit referenced in [1] shows a change that disallows access via IP address, which may be part of a broader fix, but it does not directly address the Host Header Injection vulnerability. Users should monitor the Talkyard repository for updates and consider applying input validation on the Host header or using a reverse proxy to strip injected headers as a temporary workaround.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • debiki/Talkyardllm-create2 versions
    v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1, tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular+ 1 more
    • (no CPE)range: v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1, tyse-v0.2021.02-879ef3fe1-regular through tyse-v0.2021.28-af66b6905-regular
    • (no CPE)range: v0.04.01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.