PT-2026-27627 · Pinchtab · Pinchtab

Mean3374

·

Publicado

2026-03-24

·

Atualizado

2026-03-27

·

CVE-2026-33620

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PinchTab versions v0.7.8 through v0.8.3
Description PinchTab versions v0.7.8 through v0.8.3 accepted API tokens from both the Authorization header and a token URL query parameter. When a valid API credential was sent in the URL, it could be exposed through request URIs recorded by intermediaries or client-side tooling, such as reverse proxy access logs, browser history, shell history, clipboard history, and tracing systems. This is an unsafe credential transport pattern, not a direct authentication bypass, and only affected deployments where a token was configured and a client used the query-parameter form. The v0.8.3 version included first-party flows that generated and consumed URLs containing the token. The issue was addressed in v0.8.4 by removing query-string token authentication and requiring safer header- or session-based authentication flows. The vulnerable code accepted credentials from the URL query string in internal/handlers/middleware.go. The v0.8.3 dashboard frontend also supported one-click login from the query-string token. The exposure depended on surrounding systems recording the full URL.
Recommendations Versions v0.7.8 through v0.8.3 should be updated to v0.8.4 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33620
GHSA-MRQC-3276-74F8
GO-2026-4822
SUSE-SU-2026:1135-1

Produtos afetados

Pinchtab