Pinchtab is a narrowly focused application with a concentrated vulnerability profile centered around its single product line. The recurring weakness classes—including server-side request forgery, resource-allocation issues, authentication bypass, access control failures, and code-injection flaws—reflect typical risks in web and API-driven applications where input validation, rate-limiting, and privilege boundaries require careful implementation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pinchtab over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33622HIGH PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.3` through `v0.8.5` allow arbitrary JavaScript execution through `POS | Mar 26, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-30834HIGH PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Prior to version 0.7.7, a Server-Side Request Forgery (SSRF) vulnerability in the /d | Mar 7, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-33623HIGH PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contains a Windows-only command injection issue in the orphaned Ch | Mar 26, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-33621MEDIUM PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.7` through `v0.8.4` contain incomplete request-throttling protections | Mar 26, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-33619MEDIUM PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab v0.8.3 contains a server-side request forgery issue in the optional schedul | Mar 26, 2026 | 5.5 | 20 | NO | NO |
CVE-2026-33620MEDIUM PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` through `v0.8.3` accepted the API token from a `token` URL query p | Mar 26, 2026 | 4.3 | 17 | NO | NO |
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. Versions 0.8.2 and below have a Blind SSRF vulnerability in the /download endpoint. | Mar 20, 2026 | 3.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pinchtab.
Media articles that mention a CVE ID that affects a product developed by Pinchtab — matched by CVE ID, not by vendor name.