CVE-2026-35467

HIGH

Private Key stored as extractable in browser IndexeDB

Title source: cna

Description

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.

Scores

CVSS v3 7.5
EPSS 0.0002
EPSS Percentile 6.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-522
Status published
Products (1)
CERT/CC/cveClient/encrypt-storage.js < 1.1.15
Published Apr 02, 2026
Tracked Since Apr 03, 2026