CVE-2013-2261
HIGHCryptocat < 2.0.22 - Information Disclosure via img/keygen.gif
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-2261. PoCs published by Mario Heiderich.
AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Cryptocat by leveraging an XSS attack to detect the presence of the extension via an image tag with an onload/onerror event handler.
Description
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Mario Heiderich · textremotemultiple
https://www.exploit-db.com/exploits/38636
This exploit demonstrates an information disclosure vulnerability in Cryptocat by leveraging an XSS attack to detect the presence of the extension via an image tag with an onload/onerror event handler.
Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target:
Cryptocat 2.0.21
No auth needed
Prerequisites:
Victim must have Cryptocat extension installed · Attacker must deliver the malicious HTML/JavaScript to the victim
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2013/07/10/15
Product x_refsource_misc
https://tobtu.com/decryptocat.php
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/61090
Scores
CVSS v3
7.5
EPSS
0.1106
EPSS Percentile
95.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (1)
cryptocat_project/cryptocat
< 2.0.22
Published
Nov 04, 2019
Tracked Since
Feb 18, 2026