Junglewise Threat Intelligence

CVE-2026-50635: LimeSurvey host header injection in password reset

CVE-2026-50635 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: LimeSurvey, limesurvey/limesurvey (Packagist). Vendors: LimeSurvey, Packagist.

Executive brief

LimeSurvey, a popular open-source survey tool, is vulnerable to a flaw in its password reset process. An attacker can trick the system into sending a legitimate password reset email that contains a link pointing to a malicious server. If the user clicks this link, or if their email security software automatically scans it, the attacker can capture the secret reset token and use it to take over the user's account.

Technical details

A Host Header Injection vulnerability exists in LimeSurvey's password reset mechanism. The application uses the client-supplied HTTP Host header to construct absolute URLs for password reset emails without proper validation, as the 'allowedHosts' allowlist is undefined by default. An unauthenticated remote attacker can trigger a password reset for a known username/email and provide a spoofed Host header. When the victim or an automated mail scanner interacts with the resulting link, the 'validation_key' is leaked to the attacker's server. The attacker can then replay this token against the legitimate 'newPassword' endpoint to gain full account access. The issue is addressed in versions following 7.0.0-beta1 by implementing a persisted allowed-hosts list.

Affected products

  • LimeSurvey LimeSurvey <= 7.0.0-beta1

Timeline

  • 2026-06-04: other: Fix pull request submitted
  • 2026-06-09: disclosed: Initial disclosure and NVD publication
  • 2026-06-09: patched: Fix merged into master branch
  • 2026-07-31: advisory: GitHub Advisory reviewed and updated

References

Related threats