DNS Rebinding Vulnerability in Caido Web Security Auditing Toolkit by Caido
CVE-2025-49004
7.5HIGH
What is CVE-2025-49004?
The Caido web security auditing toolkit is susceptible to a DNS rebinding vulnerability prior to version 0.48.0. This flaw enables attackers to load Caido on a domain they control, allowing them to hijack its authentication flow and potentially execute arbitrary code. Even if the user has previously configured their Caido instance, attackers can exploit this vulnerability during the initial setup phase by tricking the victim into authorizing an attacker's request, thereby gaining unauthorized access to the application. It is crucial for users to upgrade to version 0.48.0 to safeguard against this vulnerability and ensure their security environment remains intact.
Affected Version(s)
caido < 0.48.0