Hi,
can't get the author's email but there's a security issue affecting users who allow remote connections to KeePassHttp.
@pfn, please contact me at me@rplasil.name for details.
For users: make sure you don't enable remote connections to the plugin. In Options - Advanced - Host, it should be localhost