Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events
Vulnerability Description
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Summarize 代码问题漏洞
Vulnerability Description
Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在代码问题漏洞,该漏洞源于悬停摘要功能中的问题,可能导致恶意页面在攻击者控制的链接上分配合成鼠标悬停事件,导致扩展使用存储的令牌进行认证守护进程请求而不验证事件可信度。攻击者可以将本地或私有网络URL放置在可悬停链接后面,通过守护进程路由认证请求,可能访问敏感内部端点。
CVSS Information
N/A
Vulnerability Type
N/A