CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-45243: summarize before 0.15.1 (exclusive), 0 to before 0.15.1

CVE-2026-45243. CVSS 3.1 base score 6.1 (MEDIUM, Vendor/CNA). EPSS 0.00329 (percentile 0.23899), scored 2026-10-06.

Affected technology

summarize · before 0.15.1 (exclusive)
steipete

summarize · 0 to before 0.15.1
steipete

Description’s affected range: prior to 0.15.1

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Passive user interaction

What an attacker can do

Attackers can simulate runtime messages with spoofed sender identifiers to list, read, create, overwrite, or delete automation artifacts scoped to the affected tab without proper authorization checks. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality, integrity and availability impact as none.

Published

CWE
CWE-862
CCR priority
24.5 /100 (P4)
CVSS 3.1
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00329 · percentile 0.24008 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-45243.html