Retool Host Header Injection Vulnerability

Vulnerability

A host header injection vulnerability exists in self-hosted Retool deployments prior to version 3.196.0, when the BASE_DOMAIN environment variable is not set. In these cases, the HTTP host header can be manipulated, potentially leading to unauthorized actions or access.

Impact

Exploitation of this vulnerability could allow for host header injection, which can be used to manipulate the application's behavior or bypass certain security controls.

Remediation

Users can set the BASE_DOMAIN environment variable to the full URL of their Retool deployment to address this vulnerability. For versions 3.196.0 and later, this environment variable is required at startup.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
5.9
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.