{"id":"CVE-2026-42177","summary":"linux-entra-sso: PRT SSO cookie can leak to attacker-controlled hosts when broad host permissions are granted","details":"linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL + \"/*\", i.e. \"https://login.microsoftonline.com/*\". Chrome's urlFilter without a | or || anchor is substring-matched against the full request URL. The same applied rule action is modifyHeaders that attaches the Entra ID Primary Refresh Token cookie. The Firefox adapter in platform/firefox/js/platform-firefox.js:53 performs a belt-and-braces startsWith(Platform.SSO_URL) check before injecting the header; the Chrome adapter does not. When the extension holds broad host permissions through the optional_host_permissions: [\"https://*/*\"] declared in platform/chrome/manifest.json:34, a main-frame navigation to a URL whose path embeds https://login.microsoftonline.com/ causes Chrome to attach the PRT cookie to the request to the attacker-controlled host. This vulnerability is fixed in 1.8.1.","aliases":["GHSA-52rj-42vh-2rxc"],"modified":"2026-08-12T03:51:13.191975945Z","published":"2026-05-12T17:11:36.050Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-284","CWE-436"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42177.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42177.json"},{"type":"ADVISORY","url":"https://github.com/siemens/linux-entra-sso/security/advisories/GHSA-52rj-42vh-2rxc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42177"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/siemens/linux-entra-sso","events":[{"introduced":"0"},{"fixed":"88fb9104ebf584b30c8a0a032f85b9604465d251"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.8.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.8.0","v1.7.2","v1.7.1","v1.7.0","v1.6.0","v1.5.1","v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.2.0","v1.1.0","v1.0","v0.9","v0.8","v0.7","v0.6.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42177.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}