


Perceptive Security
SOC/SIEM Consultancy

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server),…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 20:13:41
Source:
nvd.nist.gov
Security Tools, Web Technologies
Dalfox, an open-source XSS scanner, contains a critical command injection vulnerability in versions prior to 2.13.0. When running in REST API server mode, the application binds to 0.0.0.0:6664 without requiring authentication by default. Attackers can exploit this by sending malicious JSON payloads to the POST /scan endpoint, which deserializes user input including FoundAction and FoundActionShell fields. These fields are passed directly to the scan options without sanitization, allowing unauthenticated remote attackers to execute arbitrary shell commands on the host system whenever a scan finding is triggered. The vulnerability affects the default configuration and has been patched in version 2.13.0.
Technical details
Mitigation steps:
Affected products:
Dalfox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45087
https://github.com/hahwul/dalfox/releases/tag/v2.13.0
https://github.com/hahwul/dalfox/security/advisories/GHSA-v25v-m36w-jp4h
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
