CVE-2026-75626

Source
https://cve.org/CVERecord?id=CVE-2026-75626
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75626.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-75626
Published
2026-08-18T10:46:54Z
Modified
2026-08-21T03:30:40Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
SpiderFoot Stored Cross-Site Scripting via Correlation Titles
Details

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75626.json"
}
References

Affected packages

Git / github.com/smicallef/spiderfoot

Affected ranges

Type
GIT
Repo
https://github.com/smicallef/spiderfoot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last Affected
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "4.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.0.2-final
v2.*
v2.0.0
v2.0.0-final
v2.0.1-final
v2.0.2-final
v2.0.3-final
v2.0.4-final
v2.0.5-final
v2.1.0-final
v2.1.1-final
v2.1.2-final
v2.1.3-final
v2.1.4-final
v2.1.5-final
v2.10-final
v2.11.0-final
v2.12.0-final
v2.2.0-final
v2.3.0-final
v2.4.0-final
v2.5.1-final
v2.6.1-final
v2.7.1-final
v2.8.0-final
v2.9.0-final
v3.*
v3.0
v3.1
v3.2
v3.3
v3.4
v3.5
v4.*
v4.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75626.json"