← volver
CVE-2026-35467

Private Key stored as extractable in browser IndexeDB

CVSS 7.5 HIGHEPSS 0.2%CWE-522
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →