Beveiligingsadvies

CVE-2026-45222

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-11 18:00:26
Laatst bijgewerkt 2026-07-14 20:01:16
Toegewezen door VulnCheck
CVSS-score 6.9
Status PUBLISHED

Beschrijving

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.