


Perceptive Security
SOC/SIEM Consultancy

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-…
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 19:08:13
Source:
nvd.nist.gov
Security Tools, Data Breach & Exfiltration
A vulnerability in Dalfox XSS scanner versions prior to 2.13.0 allows unauthenticated attackers to exfiltrate arbitrary files when the tool runs in REST API server mode. The vulnerability occurs through the custom-payload-file field which accepts attacker-controlled file paths without validation. The scanner reads lines from specified files and embeds them as XSS payloads in HTTP requests, enabling file content exfiltration. No API key authentication is required by default, making this vulnerability easily exploitable by network attackers. The issue has been fixed in version 2.13.0.
Technical details
Mitigation steps:
Affected products:
Dalfox
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45088
https://github.com/hahwul/dalfox/releases/tag/v2.13.0
https://github.com/hahwul/dalfox/security/advisories/GHSA-35wr-x7v6-9fv2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
