PT-2026-27627 · Pinchtab · Pinchtab

Mean3374

·

Published

2026-03-24

·

Updated

2026-03-27

·

CVE-2026-33620

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PinchTab versions v0.7.8 through v0.8.3
Description PinchTab versions v0.7.8 through v0.8.3 accepted API tokens from both the Authorization header and a token URL query parameter. When a valid API credential was sent in the URL, it could be exposed through request URIs recorded by intermediaries or client-side tooling, such as reverse proxy access logs, browser history, shell history, clipboard history, and tracing systems. This is an unsafe credential transport pattern, not a direct authentication bypass, and only affected deployments where a token was configured and a client used the query-parameter form. The v0.8.3 version included first-party flows that generated and consumed URLs containing the token. The issue was addressed in v0.8.4 by removing query-string token authentication and requiring safer header- or session-based authentication flows. The vulnerable code accepted credentials from the URL query string in internal/handlers/middleware.go. The v0.8.3 dashboard frontend also supported one-click login from the query-string token. The exposure depended on surrounding systems recording the full URL.
Recommendations Versions v0.7.8 through v0.8.3 should be updated to v0.8.4 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-33620
GHSA-MRQC-3276-74F8
GO-2026-4822
SUSE-SU-2026:1135-1

Affected Products

Pinchtab