VYPR
Low severityNVD Advisory· Published Jan 9, 2025· Updated Jan 10, 2025

CVE-2024-55224

CVE-2024-55224

Description

An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Vaultwarden prior to v1.32.5 contains an HTML injection vulnerability in the username field of email messages, enabling arbitrary code execution.

An HTML injection vulnerability exists in Vaultwarden versions prior to v1.32.5. The flaw allows an attacker to inject a crafted payload into the username field of an email message, leading to arbitrary code execution [1]. The root cause lies in insufficient sanitization of user-controlled input when constructing email content.

To exploit this vulnerability, an attacker must have the ability to create or modify a user account with a malicious username containing HTML or JavaScript. No special network position is required beyond normal application access. The payload is then executed when the Vaultwarden server generates and sends an email containing the tainted username, for example during password resets or notification emails.

Successful exploitation could allow an attacker to execute arbitrary code in the context of the application, potentially leading to unauthorized access, data exfiltration, or further compromise of the vault server.

The vulnerability has been patched in Vaultwarden version 1.32.5. Users are strongly advised to upgrade immediately [2]. No workaround is available other than applying the update.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
vaultwardencrates.io
< 1.32.51.32.5

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.