Junglewise Threat Intelligence

CVE-2026-52842: Lightpanda browser Same-Origin Policy bypass via URL parsing error

CVE-2026-52842 · Severity: critical · CVSS 9.3 · Published 2026-07-15

Executive brief

Lightpanda, a headless browser used for AI and automation, contains a flaw in how it identifies the 'origin' of a website. By using a specially crafted web address, an attacker can trick the browser into treating a malicious site as if it were a trusted one (such as a victim's bank or internal service). This allows the attacker to bypass standard security boundaries, potentially leading to the theft of sensitive user data or unauthorized actions performed on behalf of the user.

Technical details

A vulnerability exists in Lightpanda's URL parsing logic where the '@' character is searched for across the entire URL string rather than being restricted to the authority component. When computing a page's origin, a URL like 'http://attacker.com/@victim.com/' is correctly fetched from the attacker's server but incorrectly assigned the origin of 'victim.com'. This results in a Same-Origin Policy (SOP) bypass, allowing malicious content to execute within the security context of a different domain. The root cause is an 'Origin Validation Error' (CWE-346) in the getOrigin and getHost functions. The issue is resolved in version 0.3.1 by ensuring the parser only looks for the '@' symbol within the authority section of the URL.

Affected products

  • lightpanda-io browser < 0.3.1

Timeline

  • 2026-03-26: patched: Fix committed to main branch
  • 2026-05-26: other: Version 0.3.1 released
  • 2026-05-28: advisory: GitHub Security Advisory published
  • 2026-07-15: disclosed: CVE published to NVD

References