CVE-2026-45087Disclosure

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by default and requires no API key unless the operator explicitly passes --api-key. Because model.Options — including FoundAction and FoundActionShell — is deserialized directly from attacker-supplied JSON in POST /scan, and because dalfox.Initialize explicitly propagates those two fields into the final scan options without stripping them, any unauthenticated caller who can reach the server port can supply an arbitrary shell command that the dalfox process will execute on the host whenever a scan finding is triggered. This vulnerability is fixed in 2.13.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-15CWE-78CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Exploit tooling references are present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-27: 1Exploit Tool / Code · 2026-05-12: 1Technical Details · 2026-05-12: 105-1205-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-121
Disclosure1
2026-05-271
General1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Dalfox Server Mode Unauthenticated RCE via found-action (CVE-2026-45087) When Dalfox runs in REST API server mode (dalfox server), it binds to 0.0.0.0:6664 with no authentication by default. An unauthenticated attacker can send a POST /scan request that supplies arbitrary found-action and found-action-shell values. These are executed via exec. Command whenever a scan finding is triggered, resulting in full remote code execution on the host. 👉Affected: dalfox <= 2.12.0

    Post summary

    The post announces CVE-2026-45087, detailing an unauthenticated RCE in Dalfox server mode via POST /scan with found-action values, but offers no PoC, patch, or evidence of active exploitation.

    0002064
    187 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-45087 Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the s… https://www.cve.org/CVERecord?id=CVE-2026-45087

    Post summary

    The text notes a CVE concerning Dalfox but lacks concrete details about exploitation, patches, or technical specifics.

    00000144
    57.5K followersView on X

Explore more