An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| vaultwarden(crates.io) | 0 | 1.32.5 | N/A |
CVSS Metrics