top of page
perceptive_background_267k.jpg

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server),…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 20:13:41

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Web Technologies

Dalfox, an open-source XSS scanner, contains a critical command injection vulnerability in versions prior to 2.13.0. When running in REST API server mode, the application binds to 0.0.0.0:6664 without requiring authentication by default. Attackers can exploit this by sending malicious JSON payloads to the POST /scan endpoint, which deserializes user input including FoundAction and FoundActionShell fields. These fields are passed directly to the scan options without sanitization, allowing unauthenticated remote attackers to execute arbitrary shell commands on the host system whenever a scan finding is triggered. The vulnerability affects the default configuration and has been patched in version 2.13.0.

Technical details

Mitigation steps:

Affected products:

Dalfox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page