Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-96680

MEDIUM · 4.3 CVSS Gepubliceerd: CWE-862

Beschrijving NL

Er is een kwetsbaarheid gedetecteerd in ByteDance Coze Scraper Extension tot 2.0.2. Beïnvloed door deze kwetsbaarheid is de functie chrome.runtime.onMessageExternal.addListener van het bestand static/background/index.js van de component External Message Handler. De manipulatie van het argument body.url/paginationConfig/xPathConfig/body.urls/xPaths resulteert in ontbrekende autorisatie. De aanval kan op afstand worden gestart. De exploit is nu openbaar en kan worden gebruikt. De verkoper werd vroeg gecontacteerd over deze openbaarmaking, maar reageerde op geen enkele manier.

Origineel (Engels) tonen

A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Message Handler. The manipulation of the argument body.url/paginationConfig/xPathConfig/body.urls/xPaths results in missing authorization. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References