Junglewise Threat Intelligence

CVE-2026-45222: steipete Summarize insecure file permissions in daemon configuration

CVE-2026-45222 · Severity: medium · CVSS 6.1 · Published 2026-05-11

Technologies: Steipete Summarize, @steipete/summarize (npm). Vendors: Steipete, npm.

Executive brief

Summarize is a tool that uses a background service (daemon) to process data. In versions up to 0.14.1, the software saves sensitive information—including security tokens and API keys—using insecure file settings on Unix-like systems (such as Linux or macOS). This allows other users on the same computer to read these secrets, potentially leading to unauthorized access to the service or the theft of linked API credentials.

Technical details

A vulnerability exists in the daemon configuration storage of Summarize (up to version 0.14.1) due to incorrect permission assignment (CWE-732). The application creates the '~/.summarize' directory and 'daemon.json' file using default filesystem umask settings rather than explicit private modes (e.g., 0700/0600). On many Unix-like systems, this results in world-readable or group-readable files. A local attacker with access to the same system can read the configuration file to extract bearer tokens and persisted provider API keys. The issue was addressed in commit 0cfb0fb by enforcing private file modes and implementing a best-effort repair of existing loose permissions during configuration rewrites.

Affected products

  • steipete summarize <= 0.14.1

Timeline

  • 2026-05-07: disclosed: Initial pull request submitted by researcher
  • 2026-05-08: patched: Fix merged into main branch
  • 2026-05-11: advisory: CVE-2026-45222 published

References

Related threats