{"id":"CVE-2026-45245","title":"Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon request…","summary":"Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon request…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","cwe":["CWE-918","CWE-940"],"vendor":"steipete","product":"summarize","affected":["summarize < 0.15.1"],"patched":["summarize 0.15.1"],"published":"2026-05-18","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:16.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45245","references":[{"url":"https://github.com/steipete/summarize/commit/ecbb2c414255aa480a15d0d8b205224c14cfdbcb","label":"disclosure@vulncheck.com"},{"url":"https://github.com/steipete/summarize/pull/218","label":"disclosure@vulncheck.com"},{"url":"https://github.com/steipete/summarize/releases/tag/v0.15.2","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/summarize-unauthorized-daemon-request-via-untrusted-events","label":"disclosure@vulncheck.com"},{"url":"https://github.com/steipete/summarize/pull/218","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-05-18T20:30:27.411418Z"},"epss":0.0045,"epssPercentile":0.37036,"ingestedAt":"2026-10-08T16:52:14.681Z","slug":"CVE-2026-45245","body":"## Overview\n\nSummarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon requests using stored tokens without verifying event trustworthiness. Attackers can place local or private-network URLs behind hoverable links to route authenticated requests through the daemon, potentially accessing sensitive internal endpoints when users interact with attacker-controlled content.\n\n## Affected\n\n- `summarize < 0.15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `summarize 0.15.1`","depth":"midnight","depthScore":53,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}