CVE-2025-49004
Last modified
CVE-2025-49004 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on an attacker-controlled domain. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Caido is a web security auditing toolkit. Prior to version 0.48.0, due to the lack of protection for DNS rebinding, Caido can be loaded on an attacker-controlled domain. This allows a malicious website to hijack the authentication flow of Caido and achieve code execution. A malicious website loaded in the browser can hijack the locally running Caido instance and achieve remote command execution during the initial setup. Even if the Caido instance is already configured, an attacker can initiate the authentication flow by performing DNS rebinding. In this case, the victim needs to authorize the request on dashboard.caido.io. Users should upgrade to version 0.48.0 to receive a patch.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-49004?
How severe is CVE-2025-49004?
How do I fix CVE-2025-49004?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-48999DataEase is an open source business intelligence and data vi…8.8
- CVE-2025-4900A vulnerability classified as critical has been found in Cam…9.8
- CVE-2025-49000InvenTree is an Open Source Inventory Management System. Pri…5.7
- CVE-2025-49001DataEase is an open source business intelligence and data vi…9.8
- CVE-2025-49002DataEase is an open source business intelligence and data vi…9.8
- CVE-2025-49003DataEase is an open source business intelligence and data vi…9.8
- CVE-2025-49005Next.js is a React framework for building full-stack web app…3.7
- CVE-2025-49006Wasp (Web Application Specification) is a Rails-like framewo…8.2
- CVE-2025-49007Rack is a modular Ruby web server interface. Starting in ver…5.3
- CVE-2025-49008Atheos is a self-hosted browser-based cloud integrated devel…9.4
- CVE-2025-49009Para is a multitenant backend server/framework for object pe…6.2
- CVE-2025-4901A vulnerability classified as problematic was found in D-Lin…6.5
Are you affected by CVE-2025-49004?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
