Browse all 2 CVE security advisories affecting lightpanda-io. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-52842 | Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass — browser CWE-346 | 9.3 | Critical | 2026-07-15 |
| CVE-2026-52843 | Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode — browser CWE-346 | 9.3 | Critical | 2026-07-15 |
This page lists every published CVE security advisory associated with lightpanda-io. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.