CVE-2026-45245
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.33%
- CWE
- CWE-918, CWE-940
- Published
- 2026-05-18
- Last modified
- 2026-07-14
Affected products
- steipete summarize
- steipete summarize
Weakness type
Related vulnerabilities
- CVE-2026-88896 — EspoCRM before 10.0.4 SSRF via IPv6 Transition Address Bypass
- CVE-2026-88892 — OpenPanel SSRF via Unguarded Importer File URL Fetch
- CVE-2026-88001 — Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
- CVE-2026-87999 — Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
- CVE-2026-87996 — Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
- CVE-2026-19233 — CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized...
- CVE-2026-86771 — Snipe-IT before 8.7.0 Server-Side Request Forgery via employee_num
- CVE-2026-87821 — Lara Dashboard 0.9.2 through 1.3.1 Server-Side Request Forgery in Builder Markdown Fetch