PT-2026-45519 · Steipete+1 · Codexbar

·

CVE-2026-43625

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CodexBar versions prior to 0.32.0
Description Improper redirect handling for Amp and Ollama provider sessions allows network attackers to intercept imported browser session cookies. This occurs when a provider-controlled redirect target issues a redirect to a cleartext HTTP endpoint within the same provider domain, enabling attackers positioned on the network path to receive the cookies in cleartext HTTP requests.
Recommendations Update CodexBar to version 0.32.0 or later.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43625

Affected Products

Codexbar