PT-2025-29521 · Caido · Caido

Amrelsagaei

·

Published

2025-07-14

·

Updated

2025-07-15

·

CVE-2025-53834

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Caido versions prior to 0.49.0
Description: Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) issue exists in Caido’s toast UI component. Toast messages may reflect unsanitized user input in tools like Match&Replace and Scope, potentially allowing an attacker to execute arbitrary scripts.
Recommendations: Update to version 0.49.0 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-53834
GHSA-H8JR-C6QQ-H7M7

Affected Products

Caido