CVE-2026-102333 PUBLISHED

httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL

Assigner: VulnCheck
Reserved: 28.09.2026 Published: 28.09.2026 Updated: 29.09.2026

httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.3

Product Status

Vendor cle-b
Product httpdbg
Versions Default: unaffected
  • affected from 0 to 2.2.1 (excl.)

Credits

  • M.J Dhurgesh finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE