CVE 8.2 HIGH

CodexBar < 0.32.0 Session Cookie Exposure via HTTP Redirect_CVE-2026-43625

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling for Amp and Ollama provider sessions. Attackers can position themselves on the network path to receive cleartext HTTP requests carrying imported session cookies when a provider-controlled redirect target issues a redirect to a cleartext HTTP endpoint within the same provider domain.

Basic Information

ID CVE-2026-43625
Source VulnCheck
Published Jun 1, 2026 at 18:46

Affected Product

Vendor steipete
Product CodexBar
Affected Versions steipete CodexBar 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.