HIGH7.4npm
GHSA-2r69-qgv3-hr65· CVE-2026-45245Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links
Modified: 9/10/2026
package
pkg:npm/%40steipete/summarize
Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links
Modified: 9/10/2026
@steipete/summarize vulnerable to SSRF via podcast:transcript URL fetch
Modified: 8/20/2026
Summarize contains a missing authorization vulnerability
Modified: 9/10/2026
Summarize contains a missing authorization vulnerability
Modified: 9/10/2026
Summarize contains a path traversal vulnerability
Modified: 9/10/2026
@steipete/summarize allows local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json
Modified: 5/18/2026