CVE-2026-24853 Details
Description
Caido is a web security auditing toolkit. Prior to 0.55.0, Caido blocks non whitelisted domains to reach out through the 8080 port, and shows Host/IP is not allowed to connect to Caido on all endpoints. But this is bypassable by injecting a X-Forwarded-Host: 127.0.0.1:8080 header. This vulnerability is fixed in 0.55.0.
A vulnerability in Caido, a web security auditing toolkit, allows for a bypass of domain whitelisting restrictions. Prior to version 0.55.0, Caido blocked non-whitelisted domains from accessing port 8080 and displayed a message indicating that the host or IP was not allowed to connect. However, this restriction could be circumvented by injecting a 'X-Forwarded-Host' header with a value of '127.0.0.1:8080'. Exploiting this vulnerability could lead to remote code execution on the user's system, especially if the controlled domain was allowed to open popups, a permission not required in headless mode.
Users can update to Caido version 0.55.0 or disable Guest mode in the settings if an update is not possible.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/caido/caido/security/advisories/GHSA-3q5q-p8vj-8783 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| caido caido | < 0.55.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 24, 2026 | Initial Analysis | [email protected] |
| Feb 13, 2026 | New CVE Received | [email protected] |