FelixRiddle dev-jobs-handlebars 1.0 uses absolute...
High severity
Unreviewed
Published
Oct 16, 2025
to the GitHub Advisory Database
•
Updated Oct 16, 2025
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Last updated
Oct 16, 2025
FelixRiddle dev-jobs-handlebars 1.0 uses absolute password-reset (magic) links using the untrusted
req.headers.host
header and forces thehttp://
scheme. An attacker who can control theHost
header (or exploit a misconfigured proxy/load-balancer that forwards the header unchanged) can cause reset links to point to attacker-controlled domains or be delivered via insecure HTTP, enabling token theft, phishing, and account takeover.References