top of page
perceptive_background_267k.jpg

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server),…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Web Technologies

Critical vulnerability in Dalfox open-source XSS scanner prior to version 2.13.0. When running in REST API server mode, the application binds to all interfaces (0.0.0.0:6664) without requiring authentication by default. Attackers can exploit unsafe deserialization of user-supplied JSON in POST /scan requests to execute arbitrary shell commands on the host system. The vulnerability occurs because FoundAction and FoundActionShell fields from model.Options are directly deserialized from attacker-controlled input and propagated to scan options without validation. Any unauthenticated user who can reach the server port can achieve remote code execution when scan findings are triggered. This issue has been patched in version 2.13.0.

Technical details

Mitigation steps:

Affected products:

Dalfox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page