CVE-2026-45087 affects Dalfox versions prior to 2.13.0 when running in REST API server mode (dalfox server). In the vulnerable configuration, the server binds to 0.0.0.0:6664 by default and does not require authentication unless the operator explicitly supplies --api-key. The POST /scan endpoint deserializes attacker-controlled JSON directly into model.Options, including the FoundAction and FoundActionShell fields. dalfox.Initialize then propagates those fields into the effective scan options without stripping or neutralizing them. As a result, an unauthenticated remote attacker who can reach the server can submit a scan request containing an arbitrary shell command, which Dalfox will execute on the host when a scan finding is triggered. The issue is fixed in Dalfox 2.13.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
dalfox server to untrusted networks. Restrict access with firewall rules or other network ACLs, bind the service only to trusted interfaces instead of 0.0.0.0, and require an API key using --api-key. As an additional workaround, strip, disable, or hard-block API-supplied FoundAction and FoundActionShell values in server-side request handling so remote callers cannot trigger host command execution.Patch, then assume compromise.
github.com/hahwul/dalfox/v2 / Dalfox to version 2.13.0 or later, which fixes the vulnerable behavior. For defense in depth, require authentication for REST server mode by configuring --api-key, and ensure API-originated requests cannot set or influence FoundAction and FoundActionShell. Review any exposed Dalfox server deployments and rotate credentials or secrets present on affected hosts if compromise is suspected.No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.