CVE-2026-45222 Details
Description
Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.
A vulnerability exists in the Summarize application in versions through 0.14.1. The issue arises because the application creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems. This flaw allows local attackers to access bearer tokens and API credentials stored in the daemon configuration file. Exploitation of these permissive permissions could lead to unauthorized access to the daemon or the recovery of sensitive API keys.
Users can update to Summarize version 0.14.1 or later, where this vulnerability has been fixed. Instructions for updating can be found in the application's documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/steipete/summarize/pull/214 | CISA-ADP | Issue TrackingVendor |
| https://github.com/steipete/summarize/commit/0cfb0fb99777a87a7b02082b5e4bd449f8dd6175 | [email protected] | Source CodeVendor |
| https://github.com/steipete/summarize/pull/214 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/summarize-insecure-daemon-configuration-file-permissions | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Summarize | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion