CVE-2026-35467
CERT/CC cveClient/encrypt-storage.js, cveclient
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
- CVSS
- 7.5
- EPSS
- 0.23% 14.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.03