CVE-2026-5577 is a SQL injection vulnerability affecting Song-Li's cross_browser product up to commit ca690f0fe6954fd9bcda36d071b68ed8682a786a. The flaw exists in the details endpoint of flask/uniquemachine_app.py, where improper validation of the ID argument allows attackers to inject malicious SQL commands. The product's rolling release model means version-specific tracking is unavailable, and the vendor has not responded to disclosure notifications. The vulnerability carries a CVSS 3.1 severity rating of 7.3 (HIGH), reflecting a network-accessible attack vector with low complexity and no authentication requirements. An unauthenticated remote attacker can exploit this without user interaction to achieve confidentiality, integrity, and availability impacts. The EPSS score of 0.00037 indicates relatively low current probability of exploitation compared to the broader CVE population. The exploit has been publicly disclosed, creating potential for weaponization. However, the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation signals. Community attention remains minimal as evidenced by its inactive status on threat tracking platforms, though the availability of proof-of-concept information warrants continued monitoring for emerging attack activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2022-01-17CPE matchmatch criteria | cpe:2.3:a:songli:cross_browser_fingerprinting:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.