CVE-2013-2261

HIGH

Cryptocat < 2.0.22 - Information Disclosure via img/keygen.gif

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-2261. PoCs published by Mario Heiderich.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in Cryptocat by leveraging an XSS attack to detect the presence of the extension via an image tag with an onload/onerror event handler.

Description

Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mario Heiderich · textremotemultiple
https://www.exploit-db.com/exploits/38636

This exploit demonstrates an information disclosure vulnerability in Cryptocat by leveraging an XSS attack to detect the presence of the extension via an image tag with an onload/onerror event handler.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Cryptocat 2.0.21
No auth needed
Prerequisites: Victim must have Cryptocat extension installed · Attacker must deliver the malicious HTML/JavaScript to the victim
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Mailing List, Third Party Advisory x_refsource_misc
https://www.openwall.com/lists/oss-security/2013/07/10/15
Product x_refsource_misc
https://tobtu.com/decryptocat.php
Third Party Advisory, VDB Entry x_refsource_misc
https://www.securityfocus.com/bid/61090

Scores

CVSS v3 7.5
EPSS 0.1106
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
cryptocat_project/cryptocat < 2.0.22
Published Nov 04, 2019
Tracked Since Feb 18, 2026