---
id: CVE-2026-45243
title: >-
  Summarize prior to 0.15.1 contains a missing authorization vulnerability in
  the content script window.postMessage bridge that allows malicious pages to
  perform unauthorized operations on automation artifacts
summary: >-
  Summarize prior to 0.15.1 contains a missing authorization vulnerability in
  the content script window.postMessage bridge that allows malicious pages to
  perform unauthorized operations on automation artifacts. Attackers can
  simulate runti…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-862
vendor: steipete
product: summarize
affected:
  - summarize < 0.15.1
patched:
  - summarize 0.15.1
published: '2026-05-18'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:16.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45243'
references:
  - url: >-
      https://github.com/steipete/summarize/commit/357544063af535bd574752622f9eb94be33ee5fd
    label: disclosure@vulncheck.com
  - url: 'https://github.com/steipete/summarize/pull/222'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/steipete/summarize/releases/tag/v0.15.2'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/summarize-browser-extension-missing-authorization-via-content-script
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-19T16:22:54.365083Z'
epss: 0.00329
epssPercentile: 0.23984
ingestedAt: '2026-10-08T16:52:14.680Z'
---

## Overview

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers to list, read, create, overwrite, or delete automation artifacts scoped to the affected tab without proper authorization checks.

## Affected

- `summarize < 0.15.1`

## Remediation

Upgrade past the affected range:

- `summarize 0.15.1`
