SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Smicallef
Smicallef spiderfoot
Vendors & Products Smicallef
Smicallef spiderfoot

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Title SpiderFoot Stored Cross-Site Scripting via Correlation Titles
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-18T10:46:54.005Z

Updated: 2026-08-19T14:08:31.754Z

Reserved: 2026-08-18T01:03:25.541Z

Link: CVE-2026-75626

cve-icon Vulnrichment

Updated: 2026-08-19T14:08:26.525Z

cve-icon NVD

Status : Received

Published: 2026-08-18T11:16:51.920

Modified: 2026-08-19T15:18:08.160

Link: CVE-2026-75626

cve-icon Redhat

No data.