CVE-2026-33622 is a high-severity security-policy bypass affecting PinchTab versions v0.8.3 through v0.8.5, allowing arbitrary JavaScript execution. An authenticated attacker can exploit specific POST endpoints (`/wait` and `/tabs/{id}/wait` in `fn` mode) to execute JavaScript in the browser context, even when the `security.allowEvaluate` guard is explicitly disabled. This vulnerability carries a CVSS score of 8.8 (HIGH) due to its potential for complete compromise of confidentiality, integrity, and availability. Exploitation requires authenticated API access but does not need user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community attention, with its EPSS score being very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.8.3, <= 0.8.5CPE matchmatch criteria | cpe:2.3:a:pinchtab:pinchtab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.