PT-2026-97614 · Bytedance · Coze Scraper Extension
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ByteDance Coze Scraper Extension versions prior to 2.0.3
Description
An issue exists in the External Message Handler component within the
static/background/index.js file. The chrome.runtime.onMessageExternal.addListener() function fails to properly authorize requests, allowing remote attackers to bypass authorization by manipulating the body.url, paginationConfig, xPathConfig, body.urls, or xPaths arguments.Recommendations
Update ByteDance Coze Scraper Extension to a version newer than 2.0.2.
As a temporary mitigation, restrict the use of the
chrome.runtime.onMessageExternal.addListener() function in the static/background/index.js file.Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coze Scraper Extension