Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2026-45245— Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

CVSS 7.4 · High EPSS 0.01% · P1

Affected Version Matrix 2

VendorProductVersion RangeStatus
steipetesummarize< 0.15.1affected
ecbb2c414255aa480a15d0d8b205224c14cfdbcbunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-45245

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
Source: NVD (National Vulnerability Database)
Vulnerability Description
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
服务端请求伪造(SSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Summarize 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在代码问题漏洞,该漏洞源于悬停摘要功能中的问题,可能导致恶意页面在攻击者控制的链接上分配合成鼠标悬停事件,导致扩展使用存储的令牌进行认证守护进程请求而不验证事件可信度。攻击者可以将本地或私有网络URL放置在可悬停链接后面,通过守护进程路由认证请求,可能访问敏感内部端点。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
steipetesummarize 0 ~ 0.15.1 -

II. Public POCs for CVE-2026-45245

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 7300 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-45245

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45245 (2)

Vendor Advisories for CVE-2026-45245 (1)

Vendor Pages for CVE-2026-45245 (1)

Same Patch Batch · steipete · 2026-05-18 · 5 CVEs total

CVE-2026-452427.1 HIGHSummarize < 0.15.1 Path Traversal via slidesDir Parameter
CVE-2026-452436.1 MEDIUMSummarize < 0.15.1 Browser Extension Missing Authorization via Content Script
CVE-2026-452465.5 MEDIUMSummarize < 0.15.1 Insecure File Permissions Information Disclosure
CVE-2026-452445.4 MEDIUMSummarize < 0.15.1 Unapproved Browser Automation Execution

IV. Related Vulnerabilities

V. Comments for CVE-2026-45245

No comments yet


Leave a comment