Httpdbg · Httpdbg · CVE-2026-102333
**Name of the Vulnerable Software and Affected Versions**
httpdbg versions prior to 2.2.1
**Description**
The web interface fails to validate URL schemes in recorded HTTP request URLs that are rendered as clickable links. An attacker who can control the recorded traffic can provide URLs using the `javascript:` scheme. When these links are clicked, malicious scripts execute within the application origin, potentially granting the attacker access to captured request and response data, including headers and tokens. This is a Stored Cross-Site Scripting (XSS) issue, where a script is permanently stored on the target server and executed in the victim's browser.
**Recommendations**
Update to version 2.2.1 or later.