VDB
Sign up
LOW

GHSA-g5x8-v2ch-gj2g

Vaultwarden HTML injection vulnerability

Details

An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/vaultwarden
Introduced in: 0Fixed in: 1.32.5

Upgrade vaultwarden to 1.32.5 or newer (ecosystem crates.io).

References