CVE 6 MEDIUM

CodexBar < 0.33.0 Credential Leakage via HTTP Redirect_CVE-2026-49949

6 / 10
MEDIUM
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.

Basic Information

ID CVE-2026-49949
Source VulnCheck
Published Jun 11, 2026 at 18:55

Affected Product

Vendor steipete
Product CodexBar
Affected Versions steipete CodexBar 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.