Recon ng: Mistune Image Directive CSS Injection Vulnerability (CVE-2026-44899)
Description
A CSS injection vulnerability exists in the Image directive plugin of recon-ng due to improper validation of the :width: and :height: options. The regex used only anchors at the start of the string, allowing values that begin with digits but contain arbitrary CSS to pass validation. This leads to unescaped CSS being injected into the style attribute of rendered images, enabling attackers to create full-page overlays that can be used for phishing or UI redressing attacks. The vulnerability affects recon-ng versions >=5.1.1_1 and <5.1.2_4. A patch is available to address this issue.
CVSS v3.1
Score 4.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Image directive plugin in recon-ng uses a regex that only matches the start of the :width: and :height: option values, allowing any string beginning with digits to pass validation. When the width or height is not a plain integer, the value is inserted directly into the style attribute without escaping. This allows injection of arbitrary CSS properties, such as position:fixed and background-color, enabling an attacker to overlay malicious content visually over the entire browser viewport. The vulnerability is identified as CVE-2026-44899 and affects recon-ng versions >=5.1.1_1 and <5.1.2_4.
Potential Impact
An attacker can inject arbitrary CSS into the style attribute of images rendered by the vulnerable plugin, enabling full-page overlays that can be used for phishing or UI redressing attacks. This can deceive users by visually covering legitimate content with attacker-controlled elements. The CVSS score is 4.7 (medium severity), indicating limited confidentiality impact but significant potential for user interface manipulation.
Mitigation Recommendations
A patch is available for recon-ng that fixes this vulnerability. Users should upgrade to version 5.1.2_4 or later to remediate the issue. Until patched, avoid using untrusted input in the :width: and :height: options of the Image directive plugin or apply input validation to ensure only safe values are accepted.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-recon-ng-CVE-2026-44899
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6acaadae2cdf04f656514779
Added to database: 10/10/2026, 21:27:10 UTC
Last enriched: 10/10/2026, 21:39:23 UTC
Last updated: 10/10/2026, 21:39:23 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.