Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-75626: SpiderFoot may let attackers steal API keys via web page
CVE-2026-75626 · published 1 month ago
Summary
SpiderFoot can show information from outside sources without cleaning it first, so a malicious page could slip hidden code into the results view. When a user opens that view, the hidden code can run and capture sensitive data like API keys. Update SpiderFoot to the latest release or apply the vendor's fix, and consider limiting data sources to trusted ones.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| smicallef | spiderfoot | <= 4.0 |
Original advisory text
SpiderFoot Stored Cross-Site Scripting via Correlation Titles
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
References
- https://github.com/smicallef/spiderfoot Product
- https://github.com/smicallef/spiderfoot/issues/2012 Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75626... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-75626 Vendor Advisory
- https://www.vulncheck.com/advisories/spiderfoot-stored-cross-site-scripting-via-... Vendor Advisory
- https://github.com/smicallef/spiderfoot/blob/master/spiderfoot/correlation.py Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
9.1
Critical
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published18 Aug 2026
Updated1 Oct 2026
First seen18 Aug 2026
Track software like this
Free during beta