CVE-2026-75626 – SpiderFoot

CVSS 9.3 CRITICAL Zero Day – Immediate Deployment

“Malicious scan data can turn a routine analyst view into browser-side code execution.”

SpiderFoot contains a Critical stored cross-site scripting vulnerability in correlation results. CVE-2026-75626 allows attacker-controlled external scan data, including banners and metadata, to inject malicious HTML that executes when an operator opens the correlations view. Successful exploitation can expose sensitive browser-accessible data, including API keys. The CVSS score is 9.3, which is Critical severity.

Public proof-of-concept material is available for the vulnerability.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
CWE Classification
CWE-79
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.