CVE-2026-75626 – SpiderFoot
CVSS 9.3
CRITICAL
Zero Day – Immediate Deployment
“Malicious scan data can turn a routine analyst view into browser-side code execution.”
SpiderFoot contains a Critical stored cross-site scripting vulnerability in correlation results. CVE-2026-75626 allows attacker-controlled external scan data, including banners and metadata, to inject malicious HTML that executes when an operator opens the correlations view. Successful exploitation can expose sensitive browser-accessible data, including API keys. The CVSS score is 9.3, which is Critical severity.
Public proof-of-concept material is available for the vulnerability.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- Required
- CWE Classification
- CWE-79
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.