Command Execution Vulnerability in Career-Ops Tool by Career-Ops HQ
CVE-2026-88061
5.8MEDIUM
What is CVE-2026-88061?
The Career-Ops tool, designed for AI-assisted job searching, presented a vulnerability in its local web dashboard prior to version 0.8.0. This issue arose from the exposure of command-spawning and user-file-writing API routes without proper validation of request origins. As a result, a malicious entity could generate cross-origin localhost requests from another browser tab while the dashboard was active. In scenarios where the dashboard was not limited to loopback addresses, it became susceptible to unauthorized access from the local network, enabling command execution as the dashboard user. Thankfully, this security flaw has been resolved in version 0.8.0.
Affected Version(s)
career-ops < 0.8.0
