Steipete

Summarize

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 11.06.2026 19:17:19
  • Zuletzt bearbeitet 14.07.2026 22:17:15

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, o...

  • EPSS 0.33%
  • Veröffentlicht 11.06.2026 19:11:49
  • Zuletzt bearbeitet 14.07.2026 22:17:14

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked t...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 18.05.2026 19:03:34
  • Zuletzt bearbeitet 14.07.2026 22:16:54

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default filesystem permissions. When the refresh-free path...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 18.05.2026 19:00:54
  • Zuletzt bearbeitet 14.07.2026 22:16:54

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using store...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 18.05.2026 18:57:32
  • Zuletzt bearbeitet 14.07.2026 22:16:53

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled. Attackers can influence the agent th...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 18.05.2026 18:52:08
  • Zuletzt bearbeitet 14.07.2026 22:16:53

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequence in the slid...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 18.05.2026 18:50:45
  • Zuletzt bearbeitet 14.07.2026 22:16:53

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages w...

  • EPSS 0.1%
  • Veröffentlicht 11.05.2026 18:00:26
  • Zuletzt bearbeitet 14.07.2026 21:16:54

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and AP...