GHSA-5624-2pmv-jx46

Suggest an improvement
Source
https://github.com/advisories/GHSA-5624-2pmv-jx46
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5624-2pmv-jx46/GHSA-5624-2pmv-jx46.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-5624-2pmv-jx46
Aliases
  • CVE-2026-45243
Published
2026-05-18T21:31:50Z
Modified
2026-05-29T20:00:14.350324650Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Summarize contains a missing authorization vulnerability
Details

Summarize prior to 0.15.0 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation artifacts. Attackers can simulate runtime messages with spoofed sender identifiers to list, read, create, overwrite, or delete automation artifacts scoped to the affected tab without proper authorization checks.

Database specific
{
    "github_reviewed_at": "2026-05-29T19:49:41Z",
    "nvd_published_at": "2026-05-18T19:16:28Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

npm / @steipete/summarize

Package

Name
@steipete/summarize
View open source insights on deps.dev
Purl
pkg:npm/%40steipete%2Fsummarize

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-5624-2pmv-jx46/GHSA-5624-2pmv-jx46.json"