CVE-2026-96680 | ByteDance Coze Scraper Extension up to 2.0.2 External Message index.js chrome.runtime.onMessageExternal.addListener authorization
A vulnerability was found in ByteDance Coze Scraper Extension up to 2.0.2. It has been declared as problematic. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Message Handler. The manipulation of the argument body.url/paginationConfig/xPathConfig/body.urls/xPaths results in missing authorization.
This vulnerability is reported as CVE-2026-96680. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More