DNS Rebinding Vulnerability in Caido Web Security Auditing Toolkit by Caido
CVE-2025-49004

7.5HIGH

Key Information:

Vendor

Caido

Status
Vendor
CVE Published:
9 June 2025

What is CVE-2025-49004?

The Caido web security auditing toolkit is susceptible to a DNS rebinding vulnerability prior to version 0.48.0. This flaw enables attackers to load Caido on a domain they control, allowing them to hijack its authentication flow and potentially execute arbitrary code. Even if the user has previously configured their Caido instance, attackers can exploit this vulnerability during the initial setup phase by tricking the victim into authorizing an attacker's request, thereby gaining unauthorized access to the application. It is crucial for users to upgrade to version 0.48.0 to safeguard against this vulnerability and ensure their security environment remains intact.

Affected Version(s)

caido < 0.48.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49004 : DNS Rebinding Vulnerability in Caido Web Security Auditing Toolkit by Caido