PT-2026-45519 · Steipete+1 · Codexbar
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CodexBar versions prior to 0.32.0
Description
Improper redirect handling for Amp and Ollama provider sessions allows network attackers to intercept imported browser session cookies. This occurs when a provider-controlled redirect target issues a redirect to a cleartext HTTP endpoint within the same provider domain, enabling attackers positioned on the network path to receive the cookies in cleartext HTTP requests.
Recommendations
Update CodexBar to version 0.32.0 or later.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Codexbar