Back to CVE List

CVE-2026-49949

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.3 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Vulnerability Description

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-522
Source
NVD
Vendor
steipete
Product
CodexBar

External References

Discussion (0)

Add Comment

No comments yet. Be the first!