CVE-2026-35467

HIGH

Private Key stored as extractable in browser IndexeDB

Title source: cna
STIX 2.1

Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

References (2)

Core 2
Core References
Github PR to fix the issue
https://github.com/CERTCC/cveClient/pull/39

Scores

CVSS v3 7.5
EPSS 0.0023
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (2)
CERT/CC/cveClient/encrypt-storage.js < 1.1.15
cmu/cveclient < 1.0.24
Published Apr 02, 2026
Tracked Since Apr 03, 2026