CVE-2026-102333: medium-severity vulnerability in cle-b httpdbg
httpdbg before 2.2.1 Stored Cross-Site Scripting via javascript URL
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 90% of all CVEs
observed exploitation
nono source reports it
httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
cle-b · httpdbgReferences
https://github.com/cle-b/httpdbghttps://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3https://github.com/cle-b/httpdbg/issues/220https://github.com/cle-b/httpdbg/pull/222https://github.com/cle-b/httpdbg/releases/tag/v2.2.1https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url