Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Sylius e-commerce platform versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 contain a critical flaw in password reset token generation. The vulnerability stems from the application trusting the HTTP Host header without validation when constructing password-reset links. This allows unauthenticated attackers to manipulate the Host header in legitimate password reset requests, causing valid reset tokens to be sent to attacker-controlled domains rather than the intended administrator. The impact is severe: attackers can intercept administrator password reset tokens and gain full administrative access to Sylius installations, potentially affecting thousands of e-commerce platforms and their customer data. Any organization running vulnerable Sylius versions with administrator accounts using known or discoverable email addresses faces immediate risk of account compromise.
Casky's security skills leverage Claude AI's extended reasoning to detect the attack patterns underlying this vulnerability by analyzing request-response flows for suspicious Host header manipulation and token generation anomalies. While this specific CVE maps to zero existing MITRE ATT&ACK techniques in Casky's current skill set, practitioners using the platform would identify precursor activities through skills covering credential access patterns, particularly those detecting password reset abuse and header injection attempts. Casky would help security teams recognize the pattern of multiple password reset requests with varying Host headers targeting administrator accounts—a behavioral signature distinct from legitimate password recovery workflows. Practitioners would see findings indicating unvalidated user-supplied input influencing security-critical token generation, flagging the core weakness (CWE-640: Weak or Unauthenticated Encryption) that enables this attack chain.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-100870. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation