Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-45815

21
FAUCET Score

CVE-2023-45815 describes a cross-site scripting (XSS) vulnerability in ArchiveBox, an open-source web archiving system, specifically when using the 'wget' extractor. An attacker could craft a malicious archived page that, when viewed by a logged-in administrator in the same browser session, could execute arbitrary JavaScript. This could lead to unauthorized modification of snapshots, user accounts, or other administrative actions within ArchiveBox. The vulnerability has a CVSS score of 5.4 MEDIUM, indicating a moderate severity. It requires user interaction (viewing a malicious page) and a logged-in session for maximum impact, but can still read other archived content for non-logged-in users. The issue stems from archived content and the admin panel sharing the same host and port, bypassing typical browser security. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE. A patch is under development, and mitigations include disabling the wget extractor, ensuring users are logged out, or serving a static HTML version of the archive.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.6.2CPE matchmatch criteria
cpe:2.3:a:archivebox:archivebox:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.2
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.67%
Probability of exploitation in next 30 days
EPSS Percentile
48.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0067 is in the 82nd percentile among its peer group of 15,224 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: archiveboxFixed in: 0.9.0

Vendor Advisories (1)

pipGHSA-cr45-98w9-gwqxhigh

Viewing wget extractor output while logged in as an admin allows archived JS to execute in the admins context

Oct 19, 2023

References

en.wikipedia.org / wiki/Cross-site_request_forgery
github.com / ArchiveBox/ArchiveBox
github.com / ArchiveBox/ArchiveBox/commit/a6548df8d0aae1d3d326deb1191b128232708166
github.com / ArchiveBox/ArchiveBox/issues/239
ExploitIssue Tracking
github.com / ArchiveBox/ArchiveBox/pull/1773
github.com / ArchiveBox/ArchiveBox/security/advisories/GHSA-cr45-98w9-gwqx
PatchVendor Advisory
github.com / ArchiveBox/ArchiveBox/wiki/Configuration
github.com / ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive
github.com / ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive
github.com / ArchiveBox/ArchiveBox/wiki/Security-Overview
github.com / pypa/advisory-database/tree/main/vulns/archivebox/PYSEC-2023-229.yaml