CVE 5.3 MEDIUM

Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script_CVE-2026-45243

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Description

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers to list, read, create, overwrite, or delete automation artifacts scoped to the affected tab without proper authorization checks.

Basic Information

ID CVE-2026-45243
Source VulnCheck
Published May 18, 2026 at 18:50

Affected Product

Vendor steipete
Product summarize
Affected Versions steipete summarize 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.