Junglewise Threat Intelligence

CVE-2026-45244: steipete Summarize missing authorization in browser automation

CVE-2026-45244 · Severity: medium · CVSS 5.4 · Published 2026-05-18

Technologies: Steipete Summarize, @steipete/summarize (npm). Vendors: Steipete, npm.

Executive brief

Summarize is a browser extension used for summarizing web content and automating browser tasks. A security flaw allows malicious websites to trick the extension into performing automated actions—such as navigating the browser or using debugging tools—without the user's explicit permission. This could lead to unauthorized browser activity or the exposure of sensitive information if a user interacts with a compromised webpage while the extension's automation features are active.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Summarize Chrome extension's chat agent loop. When the automation feature is enabled, the extension fails to require per-call user confirmation before executing model-requested automation tools. An attacker can use prompt injection or malicious page content to influence the agent into invoking privileged tools, such as navigation or debugger-backed actions. This occurs because the 'runChatAgentLoop' function directly calls 'executeToolCall' without a confirmation gate. The vulnerability is remediated in version 0.15.0 by implementing a 'confirmToolCall' hook that triggers a browser confirmation prompt before any automation action is executed.

Affected products

  • steipete Summarize (Chrome Extension) < 0.15.0

Timeline

  • 2026-05-12: other: Fix proposed in pull request
  • 2026-05-13: patched: Fix merged into main branch
  • 2026-05-18: disclosed: NVD publication date
  • 2026-05-18: advisory: GitHub Advisory published

References

Related threats