Reflected Cross-Site Scripting Vulnerability in Caido's Web Security Toolkit
CVE-2025-53834
6.3MEDIUM
What is CVE-2025-53834?
A reflected cross-site scripting (XSS) vulnerability exists in the toast UI component of the Caido web security auditing toolkit, allowing unsanitized user input to be reflected in certain tools like Match&Replace and Scope. This could enable attackers to execute arbitrary scripts within a victim's browser session. The vulnerability has been addressed in version 0.49.0, which includes necessary sanitization improvements to protect against such exploits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
caido < 0.49.0
References
CVSS V3.1
Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
