Interactsh Projectdiscovery Interactsh

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Projectdiscovery Interactsh.

By the Year

In 2026 there have been 0 vulnerabilities in Projectdiscovery Interactsh. Interactsh did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 1 9.80
2023 1 6.10

It may take a day or so for new Interactsh vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Projectdiscovery Interactsh Security Vulnerabilities

Interactsh SMB Server Directory Read/Write via ANON LOGIN
CVE-2024-5262 9.8 - Critical - June 05, 2024

Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.

Files or Directories Accessible to External Parties

Interactsh <1.0.0 Subdomain Takeover via Default CNAME
CVE-2023-36474 6.1 - Medium - June 28, 2023

Interactsh is an open-source tool for detecting out-of-band interactions. Domains configured with interactsh server prior to version 1.0.0 were vulnerable to subdomain takeover for a specific subdomain, i.e `app.` Interactsh server used to create cname entries for `app` pointing to `projectdiscovery.github.io` as default, which intended to used for hosting interactsh web client using GitHub pages. This is a security issue with a self-hosted interactsh server in which the user may not have configured a web client but still have a CNAME entry pointing to GitHub pages, making them vulnerable to subdomain takeover. This allows a threat actor to host / run arbitrary client side code (cross-site scripting) in a user's browser when browsing the vulnerable subdomain. Version 1.0.0 fixes this issue by making CNAME optional, rather than default.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Projectdiscovery Interactsh or by Projectdiscovery? Click the Watch button to subscribe.

subscribe