Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在安全漏洞,该漏洞源于内容脚本window.postMessage桥接中的授权缺失问题,可能导致恶意页面执行自动化工件上的未授权操作。攻击者可以模拟带有伪造发送者标识符的运行时消息,列出、读取、创建、覆盖或删除受影响标签范围内的自动化工件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45245 | 7.4 HIGH | Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events |
| CVE-2026-45242 | 7.1 HIGH | Summarize < 0.15.1 Path Traversal via slidesDir Parameter |
| CVE-2026-45246 | 5.5 MEDIUM | Summarize < 0.15.1 Insecure File Permissions Information Disclosure |
| CVE-2026-45244 | 5.4 MEDIUM | Summarize < 0.15.1 Unapproved Browser Automation Execution |
No comments yet