PT-2025-24560 · Caido · Caido

Ry0Tak

·

Published

2025-06-09

·

Updated

2025-06-10

·

CVE-2025-49004

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Caido versions prior to 0.48.0
Description Caido is a web security auditing toolkit that lacks protection for DNS rebinding, allowing it to be loaded on an attacker-controlled domain. This enables a malicious website to hijack the authentication flow of Caido and achieve code execution. A malicious website loaded in the browser can hijack the locally running Caido instance and achieve remote command execution during the initial setup. Even if the Caido instance is already configured, an attacker can initiate the authentication flow by performing DNS rebinding, requiring the victim to authorize the request on dashboard.caido.io.
Recommendations Upgrade to version 0.48.0 to receive a patch.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-49004
GHSA-JMXF-XW2R-VJRG

Affected Products

Caido