PT-2026-99120 · Unknown · Scbe-Aethermoore
CVE-2026-57443
·
Published
2026-09-25
·
Updated
2026-09-25
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SCBE-AETHERMOORE versions 4.0.2 through 4.2.0
Description
The AetherBrowser API server (
scripts/aetherbrowser/api server.py) exposes the POST /api/ops/check-email endpoint without authentication. A remote attacker can call this endpoint to trigger the execution of the email reader.py subprocess, which connects to configured ProtonMail or Gmail accounts via IMAP. The server then returns email metadata, including the sender, subject, and a body snippet, in the JSON response. By default, the server binds to 0.0.0.0:8100 and uses a Cross-Origin Resource Sharing (CORS) configuration that allows all origins, making it accessible from any network or browser origin.Recommendations
Update to version 4.2.1.
As a temporary mitigation, restrict access to the
POST /api/ops/check-email endpoint or disable the email reader.py subprocess until the update is applied.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scbe-Aethermoore