Appsmith Origin Header Vulnerability Leading to Account Takeover

Vulnerability

A vulnerability in Appsmith prior to version 1.93 allows for account takeover by misusing the Origin header in password reset and email verification processes. The server accepted the Origin value as the base URL for email links without proper validation. This flaw enabled attackers to direct authentication tokens to their own domains, potentially leading to unauthorized access to user accounts.

Impact

Exploitation of this vulnerability allows attackers to take over user accounts by intercepting authentication tokens sent via email. Additionally, it could expose personal information such as email addresses and account details to third parties.

Reproduction

To reproduce this vulnerability, send a password reset request while manipulating the Origin header to include an attacker-controlled domain. The server will generate a link pointing to the attacker's domain, where the authentication token can be intercepted.

Remediation

Users can update to Appsmith version 1.93 or later, where this vulnerability has been fixed.

Added: Jan 12, 2026, 10:19 PM
Updated: Jan 12, 2026, 10:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.1
exploitability
7.7
remediation
7.7
relevance
2.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.