Multiple CVEs in PinchTab AI agent browser control server
Six CVEs were published against PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser, covering blind SSRF in the /download endpoint and the scheduler webhook path, API tokens accepted in URL query strings, unwired rate limiting, a JavaScript evaluation policy bypass via /wait fn mode, and a Windows-only PowerShell command injection in Chrome cleanup. Most issues were fixed in versions 0.8.3 through 0.8.5, while the /wait evaluation bypass had no patched release at time of publication.
Disclosed 20 March 2026 · Record updated 13 September 2026
Impact
Authenticated or attacker-influenced use of the agent browser server could reach internal-only services via blind SSRF, execute arbitrary JavaScript despite the operator disabling evaluation, expose API tokens through logs and browser/shell history, and on Windows execute arbitrary PowerShell as the PinchTab process user. Practical risk is reduced by local-first defaults, optional features disabled by default, and token-based access.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33081
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33619
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33620
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33621
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33622
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-33623
