PT-2025-48125 · Caido · Caido

Published

2025-11-26

·

Updated

2025-11-26

·

CVE-2025-66025

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Caido versions prior to 0.53.0
Description Caido, a web security auditing toolkit, had a flaw in its Markdown renderer used on the Findings page. This flaw allowed attacker-controlled links to be rendered without confirmation when processing user-supplied Markdown. Clicking these injected links could redirect the Caido application to a domain controlled by an attacker, potentially enabling phishing attacks.
Recommendations Update to version 0.53.0 or later.

Exploit

Fix

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66025
GHSA-CF52-H5MW-GMC2

Affected Products

Caido