Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在安全漏洞,该漏洞源于/v1/summarize守护进程端点中的路径遍历问题,可能导致认证调用者通过提供slidesDir请求参数中的绝对路径或目录遍历序列将文件写入任意目录。攻击者可以利用此漏洞将slide_*.png和slides.json文件写入任何可写目录,并通过重复提取删除指定位置的匹配文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-45245 | 7.4 HIGH | Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events |
| CVE-2026-45243 | 6.1 MEDIUM | Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script |
| CVE-2026-45246 | 5.5 MEDIUM | Summarize < 0.15.1 Insecure File Permissions Information Disclosure |
| CVE-2026-45244 | 5.4 MEDIUM | Summarize < 0.15.1 Unapproved Browser Automation Execution |
No comments yet