CodexBar是Peter Steinberger个人开发者的一款AI编程服务用量监控工具。 CodexBar 0.32.0之前版本存在安全漏洞,该漏洞源于会话Cookie泄露,可能导致网络攻击者利用Amp和Ollama提供商会话的重定向处理不当,拦截导入的浏览器会话Cookie。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-49135 | 7.1 HIGH | CodexBar < 0.32.0 Insecure Temporary File Handling in Notarization Workflow |
| CVE-2026-49134 | 7.1 HIGH | CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File |
No comments yet