OSV 1.4.0 · github-reviewed · 修改于 2026-06-13 02:28
发布时间
2026-06-13 02:28
GitHub 审查时间
2026-06-13 02:28
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/06/GHSA-j9gf-vw2f-9hrw/GHSA-j9gf-vw2f-9hrw.json
A configuration-dependent origin validation bypass was identified in Appsmith’s password reset and email verification flows on current release.
Both flows derive the email-link base URL from the request Origin header. The current validation only enforces a trusted base URL when APPSMITH_BASE_URL is configured. If that setting is unset, the application accepts the caller-supplied origin and uses it to generate token-bearing reset and verification links.
On deployments with email delivery enabled and APPSMITH_BASE_URL unset, this can cause Appsmith to send security-sensitive links whose clickable host is attacker-controlled, which can plausibly lead to account takeover after victim interaction.
The current release head at commit e77639eca4974469c1e676904851ffdaedd38111 was reviewed.
The relevant routes are publicly reachable in SecurityConfig.java:
POST /forgotPassword is permitted without authentication at line 209POST /resendEmailVerification is permitted without authentication at line 228In UserControllerCE.java, both flows copy the request Origin header into the DTO field used as the email-link base URL:
forgotPasswordRequest(...) at lines 91-94resendEmailVerification(...) at lines 189-193In UserServiceCEImpl.java, base URL validation is conditional:
@Value("${APPSMITH_BASE_URL:}") at line 113resolveSecureBaseUrl(...) at lines 132-145That method explicitly documents and implements this behavior:
APPSMITH_BASE_URL is configured, the provided URL must match itAPPSMITH_BASE_URL is unset, the provided URL is accepted for backward compatibilityThe resulting base URL is then used to construct token-bearing links:
FORGOT_PASSWORD_CLIENT_URL_FORMAT at line 149282-289EMAIL_VERIFICATION_CLIENT_URL_FORMAT at line 152931-940This means the base URL is not only used for branding or display purposes. It directly controls the clickable host of security-sensitive reset and verification links.
Note that the admin UI describes APPSMITH_BASE_URL as required for password reset and email verification links in:
app/client/src/ce/pages/AdminSettings/config/configuration.tsx at lines 41-49The reviewed self-host material indicates this protection is not fail-closed by default, which makes the vulnerable condition realistic on existing deployments where operators have not set APPSMITH_BASE_URL.
These steps were designed for validation on an Appsmith deployment that I own or am explicitly authorized to test.
release, or any build containing the affected code.APPSMITH_BASE_URL unset or blank.[email protected].Origin header:curl -i -X POST 'https://YOUR-INSTANCE/api/v1/users/forgotPassword' \
-H 'Content-Type: application/json' \
-H 'Origin: https://attacker.example' \
--data '{"email":"[email protected]"}'
https://attacker.example/... instead of the legitimate Appsmith host.curl -i -X POST 'https://YOUR-INSTANCE/api/v1/users/resendEmailVerification' \
-H 'Content-Type: application/json' \
-H 'Origin: https://attacker.example' \
--data '{"email":"[email protected]"}'
https://attacker.example/....APPSMITH_BASE_URL=https://YOUR-INSTANCE, restart the server, and repeat the same requests.Origin is rejected, or the generated links no longer follow the forged request header.Live tokens, third-party data, or unsafe exploitation material was not included in this report. The attached archive contains source excerpts, data-flow proof, safe validation notes, and supporting evidence collected from the reviewed current branch.
This is a trust-boundary failure in token-bearing email authentication flows.
Affected deployments are those where:
APPSMITH_BASE_URL is unset or blankAttacker requirements are low:
Security impact:
resolveSecureBaseUrl(...) that accepts caller-supplied origin data when APPSMITH_BASE_URL is unset.