CVE-2026-45245

HIGH

Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

Title source: cna
STIX 2.1

Description

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.

Scores

CVSS v3 7.4
EPSS 0.0033
EPSS Percentile 24.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-918 CWE-940
Status published
Products (3)
steipete/summarize < 0.15.1 (2 CPE variants)
steipete/summarize 0 - 0.15.1npm
steipete/summarize ecbb2c414255aa480a15d0d8b205224c14cfdbcb
Published May 18, 2026
Tracked Since May 19, 2026