discovered 03 Aug 2026
CVE-2025-25198-PoC
→ View on GitHubThe CVE-2025-25198-PoC tool serves as a proof-of-concept exploit targeting a host header poisoning vulnerability in Mailcow's password reset mechanism. It automatically sets up a local HTTPS listener, retrieves a CSRF token, and initiates a password reset request with a manipulated Host header to capture valid reset links from the target system's responses or callbacks. Notable features include automatic CSRF token handling, customizable attack parameters, and the ability to retry until a reset link is successfully captured.