VulnSea

steipete has 7 CVEs on record. Disclosures have slowed: 0 in the last 90 days after 7 in the 90 before. The busiest recent month was May 2026 with 5. The median CVSS is 6.1 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-862 (3).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.1
Publish → KEV
—
Last 90 days
0 prev 7

Products

  • summarize 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

steipete vulnerabilities

CVEs affecting steipete, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-53782High· 7.4
3mo ago

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 priv…

Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 priv…

▾ Twilightsteipete · summarizeEPSS 0.46%via NVD
CVE-2026-53781Medium· 4.3
3mo ago

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length heade…

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length heade…

▾ Sunlitsteipete · summarizeEPSS 0.58%via NVD
CVE-2026-45245High· 7.4PoC
4mo ago

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon request…

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extension to make authenticated daemon request…

▾ Midnightsteipete · summarizeEPSS 0.45%via NVD
CVE-2026-45244Medium· 5.4
4mo ago

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled. Attackers can influence…

▾ Sunlitsteipete · summarizeEPSS 0.38%via NVD
CVE-2026-45243Medium· 6.1
4mo ago

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runti…

▾ Sunlitsteipete · summarizeEPSS 0.33%via NVD
CVE-2026-45242High· 7.1PoC
4mo ago

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequenc…

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolute path or directory traversal sequenc…

▾ Midnightsteipete · summarizeEPSS 0.71%via NVD
CVE-2026-45222Medium· 6.1PoC
5mo ago

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer …

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer …

▾ Twilightsteipete · summarizeEPSS 0.14%via NVD
steipete vulnerabilities (CVEs) · VulnSea