Junglewise Threat Intelligence

CVE-2026-45246: steipete Summarize insecure file permissions in refresh-free path

CVE-2026-45246 · Severity: medium · CVSS 5.5 · Published 2026-05-18

Technologies: Steipete Summarize. Vendors: Steipete.

Executive brief

Summarize is a tool used for generating content summaries. A security flaw in how it updates its configuration file allows other users on the same computer to read sensitive information, such as API keys and service credentials. This occurs because the software fails to maintain private file permissions when rewriting its settings, potentially leading to unauthorized access to the user's connected AI provider accounts.

Technical details

An insecure file permission vulnerability (CWE-732) exists in Summarize versions prior to 0.15.1 within the 'refresh-free' configuration rewrite path. When updating the configuration file (~/.summarize/config.json), the application creates a temporary replacement file using default process umask permissions instead of preserving the original file's restrictive permissions. On shared Unix-like systems with a typical 022 umask, this results in the configuration file becoming world-readable. An attacker with local shell access can exploit this to read sensitive API keys and provider credentials stored in the config. The issue was fixed in version 0.15.1 (and subsequent release 0.15.2) by explicitly setting directory permissions to 0700 and file permissions to 0600 during the rewrite process.

Affected products

  • steipete Summarize < 0.15.1

Timeline

  • 2026-05-12: other: Pull request submitted to fix the vulnerability
  • 2026-05-14: patched: Fix merged into main branch
  • 2026-05-17: advisory: Version 0.15.2 released with security fixes
  • 2026-05-18: disclosed: CVE-2026-45246 published

References

Related threats