VYPR
Medium severity4.3OSV Advisory· Published Nov 26, 2025· Updated Apr 15, 2026

CVE-2025-66025

CVE-2025-66025

Description

Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page improperly handled user-supplied Markdown, allowing attacker-controlled links to be rendered without confirmation. When a user opened a finding generated through the scanner, or other plugins, clicking these injected links could redirect the Caido application to an attacker-controlled domain, enabling phishing style attacks. This issue has been patched in version 0.53.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Caido/CaidoOSV2 versions
    v0.22.1, v0.23.1, v0.24.0, …+ 1 more
    • (no CPE)range: v0.22.1, v0.23.1, v0.24.0, …
    • (no CPE)range: < 0.53.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.