PT-2026-48731 · Npm+2 · @Steipete/Summarize-Core+1

CVE-2026-53781

·

Published

2026-06-11

·

Updated

2026-06-11

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Summarize versions prior to 0.17.0
Description A resource exhaustion issue allows remote attackers to cause disk exhaustion. This occurs when media responses bypass enforced size limits due to missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers controlling a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.
Recommendations Update to version 0.17.0 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53781
GHSA-Q9XM-F36C-XM3Q

Affected Products

@Steipete/Summarize-Core
Summarize