CVE-2025-49004

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-49004
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-49004.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-49004
Aliases
  • GHSA-jmxf-xw2r-vjrg
Published
2025-06-09T20:25:45.185Z
Modified
2025-12-02T20:07:51.476741Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Hijacking Caido instance during the initial setup via DNS Rebinding to achieve RCE
Details

Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on an attacker-controlled domain. This allows a malicious website to hijack the authentication flow of Caido and achieve code execution. A malicious website loaded in the browser can hijack the locally running Caido instance and achieve remote command execution during the initial setup. Even if the Caido instance is already configured, an attacker can initiate the authentication flow by performing DNS rebinding. In this case, the victim needs to authorize the request on dashboard.caido.io. Users should upgrade to version 0.48.0 to receive a patch.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-290"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/49xxx/CVE-2025-49004.json"
}
References

Affected packages

Git / github.com/caido/caido

Affected ranges

Type
GIT
Repo
https://github.com/caido/caido
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.48.0"
        }
    ]
}

Affected versions

v0.*

v0.22.1
v0.23.1
v0.24.0
v0.24.1
v0.25.0
v0.25.3
v0.26.0
v0.27.1
v0.27.2
v0.28.0
v0.29.0
v0.29.2
v0.30.0
v0.30.1
v0.30.2
v0.30.3
v0.30.4
v0.31.0
v0.31.1
v0.32.0
v0.32.1
v0.33.0
v0.34.0
v0.34.1
v0.35.0
v0.36.0
v0.36.1
v0.37.0
v0.38.0
v0.39.0
v0.40.0
v0.41.0
v0.42.0
v0.43.0
v0.43.1
v0.44.0
v0.44.1
v0.45.0
v0.45.1
v0.46.0
v0.47.0
v0.47.1