Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2r69-qgv3-hr65 | Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links |
Tue, 19 May 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:steipete:summarize:*:*:*:*:*:*:*:* |
Mon, 18 May 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 18 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steipete
Steipete summarize |
|
| Vendors & Products |
Steipete
Steipete summarize |
Mon, 18 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content. | |
| Title | Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events | |
| Weaknesses | CWE-918 CWE-940 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-18T20:31:54.413Z
Reserved: 2026-05-11T14:14:49.613Z
Link: CVE-2026-45245
Updated: 2026-05-18T20:29:40.298Z
Status : Analyzed
Published: 2026-05-18T20:16:38.593
Modified: 2026-06-17T10:51:49.280
Link: CVE-2026-45245
No data.
OpenCVE Enrichment
Updated: 2026-05-18T20:30:05Z
Github GHSA