PatchSiren

Fabasoft CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Fabasoft CVE published 2026-09-24

CVE-2026-97155

CVE-2026-97155 debrief based on the supplied source corpus. The Fabasoft Folio Client, a locally installed component that communicates with the Fabasoft browser extension via web messaging, does not restrict which web origins may invoke its functions by default. This allows any website to invoke client functions, posing a risk to deployments with untrusted or unauthenticated internet access. Defenders sho [truncated]