Command Execution Vulnerability in Career-Ops Tool by Career-Ops HQ
CVE-2026-88061

5.8MEDIUM

Key Information:

Vendor

Santifer

Vendor
CVE Published:
10 September 2026

What is CVE-2026-88061?

The Career-Ops tool, designed for AI-assisted job searching, presented a vulnerability in its local web dashboard prior to version 0.8.0. This issue arose from the exposure of command-spawning and user-file-writing API routes without proper validation of request origins. As a result, a malicious entity could generate cross-origin localhost requests from another browser tab while the dashboard was active. In scenarios where the dashboard was not limited to loopback addresses, it became susceptible to unauthorized access from the local network, enabling command execution as the dashboard user. Thankfully, this security flaw has been resolved in version 0.8.0.

Affected Version(s)

career-ops < 0.8.0

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.