Junglewise Threat Intelligence

CVE-2025-70948: @perfood/couch-auth host header injection in mailer

CVE-2025-70948 · Severity: low · CVSS 3.1 · Published 2026-03-05

Technologies: @perfood/couch-auth (npm). Vendors: Perfood, npm.

Executive brief

@perfood/couch-auth is a Node.js authentication library used for managing user accounts and access control. A host header injection vulnerability in its email component allows attackers to intercept password reset tokens and account confirmation links by spoofing the HTTP Host header, enabling account takeover without authentication.

Technical details

A host header injection vulnerability (CWE-644, CWE-74) exists in the mailer component of @perfood/couch-auth v0.26.0 and earlier versions. The vulnerability stems from unsanitized use of the HTTP Host header when constructing password reset and email confirmation links sent to users. An attacker can send a request with a spoofed Host header, causing the mailer to embed a malicious domain in reset tokens and confirmation links. When users click these links in password reset or account verification emails, the attacker gains control over the authentication flow, enabling account takeover. Network reachable, requires user interaction (clicking malicious link), no authentication required for the attack.

Affected products

  • perfood @perfood/couch-auth 0.26.0 and earlier

Timeline

  • 2026-03-05: disclosed
  • 2026-03-06: advisory: GHSA-qw8v-34ww-6q9p published

References

Related threats