SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-75626

CRITICAL · CVSS 9.3 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

SpiderFoot is vulnerable due to its failure to properly HTML-escape correlation titles derived from external scan data, allowing attackers to inject malicious HTML elements. This critical vulnerability can lead to the execution of scripts in the operator's browser, potentially compromising sensitive information such as API keys. Organizations using SpiderFoot should prioritize immediate remediation to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75626
Severity
CRITICAL
CVSS
9.3
EPSS
0.26%

Original NVD Description

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.