This document is a security report detailing the findings from a penetration test and source code audit conducted by Cure53 on the Bitwarden Web Vault application in November 2025. The audit aimed to assess the security posture of the application and identify vulnerabilities. Six issues were discovered during the assessment, with three resolved post-assessment, while one issue retains a documented residual risk for self-hosted deployments. Two issues were accepted with potential future enhancements under consideration. The report outlines the specific vulnerabilities identified, including a 2FA bypass, unauthorized emergency access approval, and Content-Security-Policy bypasses, among others. The report also discusses the status of each issue, detailing whether they were resolved, accepted, or are still under planning. The findings emphasize the effectiveness of the Bitwarden Web Vault's security measures while acknowledging areas for improvement and ongoing research efforts.