Executive brief
Sylius, an open-source e-commerce platform, builds administrator password-reset links using untrusted request headers without validation. An attacker can forge requests with malicious Host headers to redirect password-reset tokens to attacker-controlled domains, compromising administrator accounts and gaining full control of the e-commerce system.
Technical details
The vulnerability exists in password-reset link generation, where the application constructs reset URLs using the HTTP Host header directly without validation. An unauthenticated attacker can request a password reset for a known administrator email address while supplying a forged Host header, causing the reset token to be sent to an attacker-controlled domain. This allows token interception and subsequent account takeover.
Affected products
- Sylius Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9
Timeline
- 2026-09-27: disclosed