CVE-2025-47424 Details
Description
Retool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host header can be manipulated.
A host header injection vulnerability exists in self-hosted Retool deployments prior to version 3.196.0, when the BASE_DOMAIN environment variable is not set. In these cases, the HTTP host header can be manipulated, potentially leading to unauthorized actions or access.
Users can set the BASE_DOMAIN environment variable to the full URL of their Retool deployment to address this vulnerability. For versions 3.196.0 and later, this environment variable is required at startup.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2025CISA-ADP
Assessed May 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.retool.com/disclosures/cve-2025-47424 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Retool | >= 3.18.1, <= 3.18.23 (semver) >= 3.20.1, <= 3.20.18 (semver) >= 3.22.1, <= 3.22.21 (semver) >= 3.24.1, <= 3.24.22 (semver) >= 3.26.4, <= 3.26.14 (semver) >= 3.28.3, <= 3.28.15 (semver) >= 3.30.1, <= 3.30.15 (semver) >= 3.32.1, <= 3.32.12 (semver) >= 3.33.1-stable, <= 3.33.37-stable (semver) >= 3.52.1-stable, <= 3.52.28-stable (semver) >= 3.75.1-stable, <= 3.75.25-stable (semver) >= 3.114.1-stable, <= 3.114.22-stable (semver) >= 3.148.1-stable, <= 3.148.22-stable (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 10, 2025 | CVE Modified | [email protected] |
| May 9, 2025 | New CVE Received | [email protected] |
Volerion