VYPR
Critical severity9.3NVD Advisory· Published Mar 5, 2026· Updated Apr 27, 2026

CVE-2025-70948

CVE-2025-70948

Description

A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain reset tokens and execute an account takeover via spoofing the HTTP Host header.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@perfood/couch-authnpm
<= 0.26.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.