Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-75626: SpiderFoot may let attackers steal API keys via web page

CVE-2026-75626 · published 1 month ago
Summary

SpiderFoot can show information from outside sources without cleaning it first, so a malicious page could slip hidden code into the results view. When a user opens that view, the hidden code can run and capture sensitive data like API keys. Update SpiderFoot to the latest release or apply the vendor's fix, and consider limiting data sources to trusted ones.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
smicallef spiderfoot <= 4.0
Original advisory text
SpiderFoot Stored Cross-Site Scripting via Correlation Titles
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published18 Aug 2026
Updated1 Oct 2026
First seen18 Aug 2026
Sources
CVE-2026-75626 · MITRE
Track software like this
Free during beta