Critical severity9.6NVD Advisory· Published Jan 3, 2024· Updated Jun 17, 2026
CVE-2023-39655
CVE-2023-39655
Description
A host header injection vulnerability exists in the NPM package @perfood/couch-auth versions <= 0.20.0. By sending a specially crafted host header in the forgot password request, it is possible to send password reset links to users which, once clicked, lead to an attacker-controlled server and thus leak the password reset token. This may allow an attacker to reset other users' passwords and take over their accounts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@perfood/couch-authnpm | <= 0.20.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-fqh6-6h6c-366mghsaADVISORY
- github.com/dub-flow/vulnerability-research/tree/main/CVE-2023-39655nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2023-39655ghsaADVISORY
- www.npmjs.com/package/%40perfood/couch-authnvdProductWEB
News mentions
0No linked articles in our index yet.