CVE-2025-23039

CVSS 3.1 Score 5.2 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 79

Summary

CVE-2025-23039 is a Cross-Site Scripting (XSS) vulnerability affecting the Caido web security auditing toolkit, version 0.45.0. The flaw arises from insufficient sanitization in the URL decoding tooltip of HTTP request and response editors. An attacker could exploit this weakness to inject and execute malicious scripts, which may result in the theft of sensitive information. The vulnerability has been rectified in version 0.45.1, and all users are urged to upgrade without delay. There are currently no known workarounds to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share