CVE-2026-33623
- EPSS 0.07%
- Veröffentlicht 26.03.2026 20:47:05
- Zuletzt bearbeitet 31.03.2026 16:03:21
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command injection issue in the orphaned Chrome cleanup path. When an instance is stopped, the Windows cleanup ro...
CVE-2026-33622
- EPSS 0.08%
- Veröffentlicht 26.03.2026 20:44:48
- Zuletzt bearbeitet 31.03.2026 16:11:45
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript execution through `POST /wait` and `POST /tabs/{id}/wait` when the request uses `fn` mode, e...
CVE-2026-33621
- EPSS 0.05%
- Veröffentlicht 26.03.2026 20:42:12
- Zuletzt bearbeitet 30.03.2026 13:26:50
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` through `v0.8.4` contain incomplete request-throttling protections for auth-checkable endpoints. In `v0.7.7` through `v0.8.3`, a fully i...
CVE-2026-33620
- EPSS 0.05%
- Veröffentlicht 26.03.2026 20:40:27
- Zuletzt bearbeitet 31.03.2026 15:56:34
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` through `v0.8.3` accepted the API token from a `token` URL query parameter in addition to the `Authorization` header. When a valid API c...
CVE-2026-33619
- EPSS 0.03%
- Veröffentlicht 26.03.2026 20:34:01
- Zuletzt bearbeitet 30.03.2026 13:26:50
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains a server-side request forgery issue in the optional scheduler's webhook delivery path. When a task is submitted to `POST /tasks` ...
CVE-2026-33081
- EPSS 0.04%
- Veröffentlicht 20.03.2026 09:05:01
- Zuletzt bearbeitet 23.03.2026 15:46:32
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below have a Blind SSRF vulnerability in the /download endpoint. The validateDownloadURL() function only checks the initial user-suppli...
CVE-2026-30834
- EPSS 0.02%
- Veröffentlicht 07.03.2026 15:36:30
- Zuletzt bearbeitet 11.03.2026 20:30:51
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /download endpoint allows any user with API access to induce the PinchTa...