PT-2026-97614 · Bytedance · Coze Scraper Extension

·

CVE-2026-96680

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions ByteDance Coze Scraper Extension versions prior to 2.0.3
Description An issue exists in the External Message Handler component within the static/background/index.js file. The chrome.runtime.onMessageExternal.addListener() function fails to properly authorize requests, allowing remote attackers to bypass authorization by manipulating the body.url, paginationConfig, xPathConfig, body.urls, or xPaths arguments.
Recommendations Update ByteDance Coze Scraper Extension to a version newer than 2.0.2. As a temporary mitigation, restrict the use of the chrome.runtime.onMessageExternal.addListener() function in the static/background/index.js file.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96680

Affected Products

Coze Scraper Extension