CVE-2026-75626: SpiderFoot Stored Cross-Site Scripting via Correlation Titles

Published Aug 18, 2026
·
Updated

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.

Affected Software

1 affected component
SpiderFoot SpiderFoot

Event History

Aug 18, 2026
CVE Published
via MITRE·10:46 AM
Data Sourced
via MITRE·10:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is realistically exposed to this issue?

Operators who open the correlations view for scans containing attacker-controlled external data are exposed. Relevant inputs include server banners and metadata collected from external scan data sources.

2

What does an attacker need to exploit it?

An attacker needs to cause malicious HTML with event handlers to be included in external scan data that SpiderFoot uses to build a correlation title. No SpiderFoot authentication or privileges are required for the attacker, but an operator must open the affected correlations view.

3

What is the likely impact if exploitation succeeds?

Successful exploitation can execute script in the operator's browser and may allow theft of API keys. The issue affects the browser session viewing the stored correlation result rather than requiring direct access to the SpiderFoot server.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203