Vulnerabilities/

Passbolt Browser Extension leaks password information

Severity:
Medium

Description

An issue was discovered in Passbolt Browser Extension before 4.6.2. It can send multiple requests to HaveIBeenPwned while a password is being typed, which results in an information leak.

Recommendation

Update the passbolt-browser-extension package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
passbolt-browser-extension
Anything's wrong? Let us know Last updated on June 19, 2025

This issue is available in SmartScanner Professional

See Pricing