top of page
perceptive_background_267k.jpg

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server),…

Published:

26 May 2026 at 22:00:00

Alert date:

27 May 2026 at 20:13:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Web Technologies

Dalfox, an open-source XSS scanner, contains a critical command injection vulnerability in versions prior to 2.13.0. When running in REST API server mode, the application binds to 0.0.0.0:6664 without requiring authentication by default. Attackers can exploit this by sending malicious JSON payloads to the POST /scan endpoint, which deserializes user input including FoundAction and FoundActionShell fields. These fields are passed directly to the scan options without sanitization, allowing unauthenticated remote attackers to execute arbitrary shell commands on the host system whenever a scan finding is triggered. The vulnerability affects the default configuration and has been patched in version 2.13.0.

Technical details

Mitigation steps:

Affected products:

Dalfox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page