Stored Cross-Site Scripting in SpiderFoot by Smicallef
CVE-2026-75626
9.3CRITICAL
What is CVE-2026-75626?
SpiderFoot is susceptible to a Stored Cross-Site Scripting vulnerability due to improper HTML escaping of correlation titles derived from external scan data sources. Malicious actors can exploit this flaw to inject harmful HTML elements, which may include event handlers. When a user views the correlation results, these scripts can execute in the operator's browser, potentially leading to the theft of sensitive information such as API keys. This issue underscores the importance of input validation and proper escaping in web applications to ensure the safety of users against web-based attacks.
Affected Version(s)
spiderfoot 0 <= 4.0
