{"id":"CVE-2026-102333","published":"2026-09-28T23:17:01.677","lastModified":"2026-09-29T13:17:50.217","description":"httpdbg before 2.2.1 fails to validate URL schemes in recorded HTTP request URLs rendered as clickable links in the web interface. Attackers controlling traffic recorded by httpdbg can supply javascript: scheme URLs that execute malicious scripts in the application origin when clicked, allowing access to captured request and response data including headers and tokens.","cvssScore":6.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/cle-b/httpdbg","tags":[]},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97","tags":[]},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302","tags":[]},{"url":"https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3","tags":[]},{"url":"https://github.com/cle-b/httpdbg/issues/220","tags":[]},{"url":"https://github.com/cle-b/httpdbg/pull/222","tags":[]},{"url":"https://github.com/cle-b/httpdbg/releases/tag/v2.2.1","tags":[]},{"url":"https://www.vulncheck.com/advisories/httpdbg-before-2.2.1-stored-cross-site-scripting-via-javascript-url","tags":[]},{"url":"https://github.com/cle-b/httpdbg/issues/220","tags":[]}],"exploitRefs":[{"url":"https://github.com/cle-b/httpdbg","tags":[]},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/hooks/recordhttp2.py#L88-L97","tags":[]},{"url":"https://github.com/cle-b/httpdbg/blob/v2.2.0/httpdbg/webapp/static/index.htm#L302","tags":[]},{"url":"https://github.com/cle-b/httpdbg/commit/121845b41c19ddaf30b51be0797bc2ff4847d8b3","tags":[]},{"url":"https://github.com/cle-b/httpdbg/issues/220","tags":[]},{"url":"https://github.com/cle-b/httpdbg/pull/222","tags":[]},{"url":"https://github.com/cle-b/httpdbg/releases/tag/v2.2.1","tags":[]},{"url":"https://github.com/cle-b/httpdbg/issues/220","tags":[]}],"hasPoc":true,"ai":null}