CVE-2026-45244 Details
Description
Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation feature is enabled. Attackers can influence the agent through malicious page or summary content to invoke enabled extension automation tools such as navigation or debugger-backed actions, bypassing the final user approval step when a user interacts with attacker-controlled content.
A missing authorization vulnerability has been identified in the Steipete Summarize Chrome extension, affecting versions prior to 0.15.1. This vulnerability allows attackers to execute browser automation actions without user approval for each individual action, bypassing a crucial confirmation step. Exploitation is possible when the extension's automation feature is enabled, and attackers can manipulate the agent by injecting malicious content into pages or summaries. This manipulation can trigger automation tools like navigation or debugger-related actions, all without the user's consent.
Users can update to Steipete Summarize version 0.15.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/steipete/summarize/commit/e64fe3ecd1bb4fdc181dcfa88c96b9e1914ced0e | [email protected] | Patch |
| https://github.com/steipete/summarize/pull/219 | [email protected] | ExploitIssue TrackingPatch |
| https://github.com/steipete/summarize/releases/tag/v0.15.2 | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/summarize-unapproved-browser-automation-execution | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| steipete summarize | < 0.15.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |