top of page
perceptive_background_267k.jpg

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-…

Published:

26 mei 2026 om 22:00:00

Alert date:

27 mei 2026 om 19:08:13

Source:

nvd.nist.gov

Click to open the original link from this advisory

Security Tools, Data Breach & Exfiltration

A vulnerability in Dalfox XSS scanner versions prior to 2.13.0 allows unauthenticated attackers to exfiltrate arbitrary files when the tool runs in REST API server mode. The vulnerability occurs through the custom-payload-file field which accepts attacker-controlled file paths without validation. The scanner reads lines from specified files and embeds them as XSS payloads in HTTP requests, enabling file content exfiltration. No API key authentication is required by default, making this vulnerability easily exploitable by network attackers. The issue has been fixed in version 2.13.0.

Technical details

Mitigation steps:

Affected products:

Dalfox

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page