Description
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Published: 2026-08-18
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SpiderFoot does not escape correlation titles that are constructed from data received from external scan sources such as server banners and metadata. An attacker can embed malicious HTML elements with event handlers into these titles. When a user opens the correlations view in a browser, the injected scripts run in the context of the operator and can exfiltrate sensitive information like API keys. This constitutes a high‑impact client‑side code execution vulnerability.

Affected Systems

The vulnerability affects all installed instances of SpiderFoot provided by the vendor smicallef. No specific patches or version numbers are listed in the current data, so all currently supported releases are potentially affected until a remediation is applied.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. No EPSS score is available, but the lack of KEV listing suggests no known widespread exploitation yet. The feasible attack vector is the injection of crafted data into the correlation titles through external scan feeds; an attacker would need to supply such data, which is then displayed when the operators view the correlations page. If successful, the script would execute in the operator’s browser and allow exfiltration of API keys or other credentials stored locally.

Generated by OpenCVE AI on August 18, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest SpiderFoot patch or upgrade to a fixed release promptly
  • If upgrading is not immediately possible, disable or restrict external scan data feeds that supply server banners and metadata for correlation titles
  • After remediation, monitor browser console and logs for any anomalous script activity or unauthorized key exfiltration

Generated by OpenCVE AI on August 18, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Smicallef
Smicallef spiderfoot
Vendors & Products Smicallef
Smicallef spiderfoot

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Title SpiderFoot Stored Cross-Site Scripting via Correlation Titles
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

Smicallef Spiderfoot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-19T14:08:31.754Z

Reserved: 2026-08-18T01:03:25.541Z

Link: CVE-2026-75626

cve-icon Vulnrichment

Updated: 2026-08-19T14:08:26.525Z

cve-icon NVD

Status : Received

Published: 2026-08-18T11:16:51.920

Modified: 2026-08-19T15:18:08.160

Link: CVE-2026-75626

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:39:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')