


Perceptive Security
SOC/SIEM Consultancy

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 20:13:41
Source:
nvd.nist.gov
Security Tools, Data Breach & Exfiltration
CVE-2026-45088 affects Dalfox XSS scanner versions prior to 2.13.0. When running in REST API server mode, the tool is vulnerable to arbitrary file disclosure through unauthenticated requests. Attackers can exploit the custom-payload-file parameter to read any file accessible to the Dalfox process by manipulating JSON deserialization. The vulnerability allows remote file exfiltration through scan traffic directed at attacker-controlled URLs. This issue has been patched in version 2.13.0.
Technical details
Mitigation steps:
Affected products:
Dalfox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45088
https://github.com/hahwul/dalfox/releases/tag/v2.13.0
https://github.com/hahwul/dalfox/security/advisories/GHSA-35wr-x7v6-9fv2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
