Executive brief
Dalfox, a tool used for scanning web applications for vulnerabilities, contains a flaw in its server mode that allows unauthenticated attackers to execute arbitrary commands on the host system. By default, the server does not require an API key and allows users to specify shell commands that run automatically when a vulnerability is found. An attacker can exploit this by sending a malicious scan request, leading to full control over the server, data theft, or service disruption.
Technical details
Dalfox's REST API server mode (cmd/server.go) defaults to binding on 0.0.0.0 and does not enforce authentication unless an API key is explicitly configured. The 'POST /scan' endpoint deserializes the 'model.Options' struct directly from user-supplied JSON, which includes 'FoundAction' and 'FoundActionShell' fields. These fields are propagated without sanitization to the scanning engine. When a scan finding is triggered—which an attacker can guarantee by pointing the scan at a controlled reflective target—the 'foundAction' function in 'pkg/scanning/foundaction.go' executes the attacker-provided shell command using 'exec.Command'. This allows for full OS-level command execution with the privileges of the Dalfox process.
Affected products
- hahwul dalfox <= 2.12.0
Timeline
- 2026-05-07: disclosed: Initial disclosure on GitHub
- 2026-05-12: advisory: Published GHSA advisory
- 2026-05-12: patched: Fixed in version 2.13.0