CVE-2026-52843
CRITICALLightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode
Title source: cnaDescription
Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached session cookies to every HTTP request, ignoring credentials: omit, credentials: same-origin, credentials: include, and XMLHttpRequest.withCredentials, allowing an attacker-controlled origin in a Lightpanda session to issue authenticated cross-origin requests against a victim origin. This issue is fixed in version 0.2.9.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/lightpanda-io/browser/security/advisories/GHSA-36mm-v3c2-24cc
X_Refsource_Misc x_refsource_misc
https://github.com/lightpanda-io/browser/pull/2155
X_Refsource_Misc x_refsource_misc
https://github.com/lightpanda-io/browser/commit/2cdaac780bed65db98bbb6ed2ad5bc6011863c76
X_Refsource_Misc x_refsource_misc
https://github.com/lightpanda-io/browser/releases/tag/0.2.9
Scores
CVSS v3
9.3
EPSS
0.0017
EPSS Percentile
7.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-346
Status
published
Products (1)
lightpanda-io/browser
< 0.2.9
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026