Summarize是Peter Steinberger个人开发者的一款支持多来源的快速摘要工具。 Summarize 0.15.1之前版本存在安全漏洞,该漏洞源于无刷新配置重写路径中的不安全文件权限问题,可能导致本地用户通过利用默认文件系统权限读取敏感凭据。当无刷新路径重写配置文件时,它使用默认进程umask权限创建替换文件,而不是保留原始文件权限,将包含API密钥和提供者凭据的配置文件暴露给共享类Unix系统上的其他本地用户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45245 | 7.4 HIGH | Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events |
| CVE-2026-45242 | 7.1 HIGH | Summarize < 0.15.1 Path Traversal via slidesDir Parameter |
| CVE-2026-45243 | 6.1 MEDIUM | Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script |
| CVE-2026-45244 | 5.4 MEDIUM | Summarize < 0.15.1 Unapproved Browser Automation Execution |
No comments yet