


Perceptive Security
SOC/SIEM Consultancy

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server),…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 19:08:13
Source:
nvd.nist.gov
Security Tools, Web Technologies
Critical vulnerability in Dalfox open-source XSS scanner prior to version 2.13.0. When running in REST API server mode, the application binds to all interfaces (0.0.0.0:6664) without requiring authentication by default. Attackers can exploit unsafe deserialization of user-supplied JSON in POST /scan requests to execute arbitrary shell commands on the host system. The vulnerability occurs because FoundAction and FoundActionShell fields from model.Options are directly deserialized from attacker-controlled input and propagated to scan options without validation. Any unauthenticated user who can reach the server port can achieve remote code execution when scan findings are triggered. This issue has been patched in version 2.13.0.
Technical details
Mitigation steps:
Affected products:
Dalfox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45087
https://github.com/hahwul/dalfox/releases/tag/v2.13.0
https://github.com/hahwul/dalfox/security/advisories/GHSA-v25v-m36w-jp4h
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
