← Späť na vyhľadávanie CVE

CVE-2026-45243

Summarize

Popis

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers to list, read, create, overwrite, or delete automation artifacts scoped to the affected tab without proper authorization checks.

CVSS 6.1EPSS 0.19499999999999998%Riziko 0.62
Zobraziť zdroj
Zverejnené
2026-05-18 19:16:28
Dotknuté verzie
<0.15.1
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N