VDB
Sign up

package

npm/@steipete/summarize

pkg:npm/%40steipete/summarize

HIGH7.4npm
GHSA-2r69-qgv3-hr65· CVE-2026-45245

Summarize's hover summary feature allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links

Modified: 9/10/2026

MEDIUM6.1npm
GHSA-qp7v-gjgg-4mj6· CVE-2026-45222

@steipete/summarize allows local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json

Modified: 5/18/2026