HIGH 8.1 NVD
CVE-2026-81179
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOST
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link can disclose the reset token, allowing the attacker to reset the victim's password and take over the account. Exploitation also requires a configured email gateway and an email address for the victim, while some reverse proxy configurations may reject the hostile Host header. This issue is fixed in version 2026.58.
References
- https://github.com/Syslifters/sysreptor/commit/7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea
- https://github.com/Syslifters/sysreptor/releases/tag/2026.58
- https://github.com/Syslifters/sysreptor/security/advisories/GHSA-9x2r-5pff-8w6c
This high severity vulnerability with a CVSS score of 8.1 was published on 2026-09-18 via NVD.
vulnfeed aggregates 14649 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.