Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via custom-payload-file in github.com/hahwul/dalfox
custom-payload-file
{ "url": "https://pkg.go.dev/vuln/GO-2026-5070", "review_status": "UNREVIEWED" }
"https://vuln.go.dev/ID/GO-2026-5070.json"