Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicious podcast:transcript URL values. Attackers can bypass protections through DNS rebinding and redirect-based techniques, as redirect targets are not revalidated and hostnames are not resolved before request dispatch, exposing internal service responses through the summarization flow.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Steipete
Steipete summarize |
|
| Vendors & Products |
Steipete
Steipete summarize |
Thu, 11 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript content from loopback addresses, link-local addresses, RFC 1918 private ranges, or other reserved destinations by supplying malicious podcast:transcript URL values. Attackers can bypass protections through DNS rebinding and redirect-based techniques, as redirect targets are not revalidated and hostnames are not resolved before request dispatch, exposing internal service responses through the summarization flow. | |
| Title | Summarize < 0.17.0 SSRF via podcast:transcript URL fetch | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-11T19:24:01.385Z
Reserved: 2026-06-10T20:14:32.826Z
Link: CVE-2026-53782
No data.
Status : Deferred
Published: 2026-06-11T20:16:25.787
Modified: 2026-06-11T20:50:49.480
Link: CVE-2026-53782
No data.
OpenCVE Enrichment
Updated: 2026-06-11T22:15:09Z