{"id":"CVE-2026-45222","aliases":["GHSA-qp7v-gjgg-4mj6"],"url":"https://o3.security/vulnerability/CVE-2026-45222","summary":"Summarize Insecure Daemon Configuration File Permissions","details":"Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, allowing local attackers to read bearer tokens and API credentials stored in ~/.summarize/daemon.json. A local attacker can exploit these permissive permissions to read the daemon bearer token and persisted provider credentials, enabling unauthorized access to the daemon or recovery of sensitive API keys.","published":"2026-05-11T18:00:26.205Z","modified":"2026-08-07T11:51:11.681684557Z","cvss":null,"epss":{"score":0.00098,"percentile":0.00897,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@steipete/summarize","fixedVersion":"0.15.0"}],"fix":{"url":"https://github.com/steipete/summarize/commit/0cfb0fb99777a87a7b02082b5e4bd449f8dd6175","label":"steipete/summarize@0cfb0fb"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45222.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45222"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/summarize-insecure-daemon-configuration-file-permissions"},{"type":"REPORT","url":"https://github.com/steipete/summarize/pull/214"},{"type":"FIX","url":"https://github.com/steipete/summarize/commit/0cfb0fb99777a87a7b02082b5e4bd449f8dd6175"},{"type":"PACKAGE","url":"https://github.com/steipete/summarize"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:51:11.681684557Z"}}