
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33622 is a security policy bypass vulnerability in PinchTab, a standalone HTTP server that gives AI agents direct control over a Chrome browser. Affecting versions v0.8.3 through v0.8.5, the flaw allows authenticated callers to execute arbitrary JavaScript in a browser tab context via the POST /wait and POST /tabs/{id}/wait endpoints using fn mode, even when the security.allowEvaluate setting is explicitly disabled. The vulnerability was published on March 22, 2026, by researcher Yesuhei and reviewed by the GitHub Advisory Database on March 24, 2026. It carries a CVSS v3.1 score of 8.8 (High) and a CVSS v4.0 score of 6.1 (Medium/Moderate) (GitHub Advisory, PinchTab Advisory).
The root cause is an inconsistent enforcement of the security.allowEvaluate policy guard across HTTP endpoints (CWE-94: Code Injection; CWE-284: Improper Access Control; CWE-693: Protection Mechanism Failure). While POST /evaluate correctly checks evaluateEnabled() and returns HTTP 403 with evaluate_disabled when the policy is off, the handleWaitCore function in wait.go omits this check entirely. In fn mode, the handler interpolates the caller-supplied req.Fn string directly into a JavaScript template via fmt.Sprintf and passes it to chromedp.Evaluate, executing it in the live browser tab context without any policy validation. Exploitation requires network access to the PinchTab server and a valid API bearer token, but no additional privileges beyond that (GitHub Advisory, PinchTab Advisory).
A successful exploit allows an authenticated attacker to execute arbitrary JavaScript within any reachable Chrome browser tab managed by PinchTab, bypassing the operator's explicit security.allowEvaluate = false configuration. This enables reading or exfiltrating sensitive data from browser memory and page state (e.g., session tokens, form data, cookies accessible via JavaScript), modifying page content, and performing actions on behalf of authenticated users within those browser sessions. The inconsistency between /evaluate and /wait policy enforcement makes the configured security boundary unreliable, undermining operator trust in the access control model (GitHub Advisory).
A proof-of-concept exploit consisting of a complete 4-step curl command sequence is publicly available in the official security advisory, demonstrating arbitrary JavaScript execution on a real PinchTab deployment (PinchTab Advisory). Feedly threat intelligence rates the PoC confidence as high and classifies it as a real exploit. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.095% (0.134% per GitHub Advisory), placing it in the 33rd percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
/evaluate to verify that security.allowEvaluate is disabled and the endpoint returns {"code": "evaluate_disabled"}:curl -s -X POST http://localhost:9867/evaluate \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{"expression":"1+1"}'tabId:curl -s -X POST http://localhost:9867/navigate \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{"url":"https://example.com"}'/wait with a malicious fn expression (e.g., to set a global variable, exfiltrate data, or manipulate page state):curl -s -X POST http://localhost:9867/wait \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{"tabId":"<TAB_ID>","fn":"(function(){window._poc_executed=true;return true})()","timeout":5000}'curl -s -X POST http://localhost:9867/wait \
-H "Authorization: Bearer <TOKEN>" \
-H "Content-Type: application/json" \
-d '{"tabId":"<TAB_ID>","fn":"window._poc_executed === true","timeout":3000}'Expected response: {"waited": true, "elapsed": 0, "match": "fn"} (PinchTab Advisory)./wait or /tabs/{id}/wait endpoints on the PinchTab server (default port 9867) containing a fn field with JavaScript expressions beyond simple boolean predicates; requests to these endpoints from IP addresses not associated with authorized AI agent infrastructure./wait with fn payloads containing function expressions, IIFE patterns (e.g., (function(){...})()), or references to sensitive browser APIs (document.cookie, localStorage, fetch); absence of corresponding evaluate_disabled errors despite security.allowEvaluate = false being configured.window._poc_executed, injected script tags, or altered page content) not attributable to normal agent workflows; unauthorized navigation events or form submissions originating from the browser context.As of the advisory publication date (March 22, 2026), no patched release was available, though a fix had been developed in the current worktree applying the same security.allowEvaluate policy check to fn mode in /wait endpoints. Operators should monitor the PinchTab repository for a patched release and upgrade immediately when available. In the interim, restrict network access to the PinchTab server to trusted hosts only, limit distribution of the server API token to the minimum necessary operators, and consider disabling or blocking the /wait and /tabs/{id}/wait endpoints at the network layer if fn mode is not required for operations (GitHub Advisory, PinchTab Advisory).
The vulnerability was reported by researcher Yesuhei and published by maintainer luigi-agosti via the official GitHub Security Advisory on March 22, 2026. Coverage has appeared on vulnerability tracking platforms including cvefeed.io, vuldb.com, and db.gcve.eu, as well as a dedicated write-up on infinitsec.net. No significant broader media coverage or notable social media discussion has been identified beyond standard vulnerability database aggregation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."