Stored Cross-Site Scripting in SpiderFoot by Smicallef
CVE-2026-75626

9.3CRITICAL

Key Information:

Vendor

Smicallef

Vendor
CVE Published:
18 August 2026

What is CVE-2026-75626?

SpiderFoot is susceptible to a Stored Cross-Site Scripting vulnerability due to improper HTML escaping of correlation titles derived from external scan data sources. Malicious actors can exploit this flaw to inject harmful HTML elements, which may include event handlers. When a user views the correlation results, these scripts can execute in the operator's browser, potentially leading to the theft of sensitive information such as API keys. This issue underscores the importance of input validation and proper escaping in web applications to ensure the safety of users against web-based attacks.

Affected Version(s)

spiderfoot 0 <= 4.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.