CVE-2026-45246

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default filesystem permissions. When the refresh-free path rewrites the configuration file, it creates the replacement with default process umask permissions instead of preserving the original file permissions, exposing the config file containing API keys and provider credentials to other local users on shared Unix-like systems.
Configurations

Configuration 1 (hide)

cpe:2.3:a:steipete:summarize:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-18 20:16

Updated : 2026-07-14 22:16


NVD link : CVE-2026-45246

Mitre link : CVE-2026-45246

CVE.ORG link : CVE-2026-45246


JSON object : View

Products Affected

steipete

  • summarize
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource