CVE-2026-49949 PUBLISHED

CodexBar < 0.33.0 Credential Leakage via HTTP Redirect

Assigner: VulnCheck
Reserved: 02.06.2026 Published: 11.06.2026 Updated: 12.06.2026

CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor steipete
Product CodexBar
Versions Default: affected
  • affected from 0 to 0.33.0 (excl.)

Credits

  • Chia Min Jun Lennon finder

References

Problem Types

  • Insufficiently Protected Credentials CWE