CVE-2026-33081 identifies a blind Server-Side Request Forgery (SSRF) vulnerability in PinchTab versions 0.8.2 and below, affecting its /download endpoint. This flaw allows an attacker to bypass initial URL validation by leveraging the embedded Chromium browser to follow redirects to internal network addresses, potentially reaching internal-only services from the PinchTab host. Rated with a LOW CVSS score of 3.7, exploitation requires high attack complexity as it depends on an attacker-controlled page and the `security.allowDownload` setting being enabled, which is disabled by default, limiting its real-world impact to low integrity. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.3CPE matchmatch criteria | cpe:2.3:a:pinchtab:pinchtab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.