Vulnerability Description
Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Steipete | Summarize | < 0.15.1 |
Related Weaknesses (CWE)
References
- https://github.com/steipete/summarize/commit/ecbb2c414255aa480a15d0d8b205224c14cPatch
- https://github.com/steipete/summarize/pull/218ExploitIssue TrackingPatch
- https://github.com/steipete/summarize/releases/tag/v0.15.2Release Notes
- https://www.vulncheck.com/advisories/summarize-unauthorized-daemon-request-via-uThird Party Advisory
- https://github.com/steipete/summarize/pull/218ExploitIssue TrackingPatch
FAQ
What is CVE-2026-45245?
CVE-2026-45245 is a vulnerability with a CVSS score of 7.4 (HIGH). Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension...
How severe is CVE-2026-45245?
CVE-2026-45245 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45245?
Check the references section above for vendor advisories and patch information. Affected products include: Steipete Summarize.