CVE-2026-45245

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
Configurations

Configuration 1 (hide)

cpe:2.3:a:steipete:summarize:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-18 20:16

Updated : 2026-07-14 22:16


NVD link : CVE-2026-45245

Mitre link : CVE-2026-45245

CVE.ORG link : CVE-2026-45245


JSON object : View

Products Affected

steipete

  • summarize
CWE
CWE-918

Server-Side Request Forgery (SSRF)

CWE-940

Improper Verification of Source of a Communication Channel