


Perceptive Security
SOC/SIEM Consultancy

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the output, output-…
Published:
26 May 2026 at 22:00:00
Alert date:
27 May 2026 at 19:08:13
Source:
nvd.nist.gov
Security Tools, Web Technologies
CVE-2026-45089 affects Dalfox, an open-source XSS scanner, prior to version 2.13.0. When running in REST API server mode, the vulnerability allows unauthenticated attackers to create or append to arbitrary files on the host filesystem. The issue stems from improper handling of output, output-all, and debug fields that are deserialized from attacker requests and passed to the logging system. The logger opens attacker-supplied file paths with write permissions, and this occurs outside the IsLibrary guard, making it exploitable in server mode. No API key is required in default configuration, making this vulnerability easily exploitable by network attackers.
Technical details
Mitigation steps:
Affected products:
Dalfox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45089
https://github.com/hahwul/dalfox/releases/tag/v2.13.0
https://github.com/hahwul/dalfox/security/advisories/GHSA-8hf9-3q64-q2qf
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
