CVE-2025-53834: Caido
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s toast UI component in versions prior to 0.49.0. Toast messages may reflect unsanitized user input in certain tools such as Match&Replace and Scope. This could allow an attacker to craft input that results in arbitrary script execution. Version 0.49.0 fixes the issue.
Affected products
- Caido Caido: before 0.49.0 (fixed in 0.49.0)
Published 2025-07-14. Last modified 2026-06-17.