No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Santifer
Santifer career-ops |
|
| Vendors & Products |
Santifer
Santifer career-ops |
Thu, 10 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or restricting clients to loopback addresses. A malicious page in another browser tab could send cross-origin localhost requests while the dashboard was running, and a dashboard bound beyond loopback could receive direct requests from the local network. Both paths allowed unauthenticated command execution as the dashboard user, but npm installations were unaffected because web/ is excluded from the published package. This issue is fixed in version 0.8.0. | |
| Title | career-ops: Local dashboard API accepted cross-origin and non-loopback requests, allowing unauthenticated command execution | |
| Weaknesses | CWE-1385 CWE-352 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-15T15:36:43.784Z
Reserved: 2026-09-09T21:22:45.434Z
Link: CVE-2026-88061
Updated: 2026-09-15T15:36:39.692Z
Status : Received
Published: 2026-09-10T20:17:31.540
Modified: 2026-09-15T16:17:37.447
Link: CVE-2026-88061
No data.
OpenCVE Enrichment
Updated: 2026-09-13T19:59:53Z