GHSA-qp7v-gjgg-4mj6

Suggest an improvement
Source
https://github.com/advisories/GHSA-qp7v-gjgg-4mj6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qp7v-gjgg-4mj6/GHSA-qp7v-gjgg-4mj6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qp7v-gjgg-4mj6
Aliases
Published
2026-05-11T21:31:34Z
Modified
2026-05-18T17:11:25Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
@steipete/summarize allows local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json
Details

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.

Database specific
{
    "cwe_ids":  [
        "CWE-732"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-18T16:47:44Z",
    "nvd_published_at":  "2026-05-11T19:16:27Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / @steipete/summarize

Package

Name
@steipete/summarize
View open source insights on deps.dev
Purl
pkg:npm/%40steipete/summarize

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.15.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-qp7v-gjgg-4mj6/GHSA-qp7v-gjgg-4mj6.json"