Feed/CVE-2026-53781
CVE-2026-53781MEDIUMCVSS 4.3

@steipete/summarize is Vulnerable to Disk Exhaustion via Crafted Media Responses

Published Jun 11, 2026·Updated Jul 27, 2026

NVD Description

Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.

Affected Packages (1)

@steipete/summarize-coreNPM
Fixed in 0.17.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free