CVE-2025-23039
CVSS 3.1 Score 5.2 of 10 (medium)
Details
Published Jan 17, 2025
CWE ID 79
Summary
CVE-2025-23039 is a Cross-Site Scripting (XSS) vulnerability affecting the Caido web security auditing toolkit, version 0.45.0. The flaw arises from insufficient sanitization in the URL decoding tooltip of HTTP request and response editors. An attacker could exploit this weakness to inject and execute malicious scripts, which may result in the theft of sensitive information. The vulnerability has been rectified in version 0.45.1, and all users are urged to upgrade without delay. There are currently no known workarounds to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.