MouseTooltipTranslator Chrome Extension Server-Side Request Forgery Vulnerability

Vulnerability

A server-side request forgery (SSRF) vulnerability has been identified in the MouseTooltipTranslator Chrome extension, version 0.1.127. This vulnerability allows an attacker to manipulate the extension into sending requests to arbitrary URLs. The issue arises because the 'pdf.mjs' script, which is vulnerable to SSRF, is imported into 'viewer.html'. Since 'viewer.html' can be accessed from any URL, an attacker can exploit this to make requests from the user's browser to potentially harmful locations.

Impact

Exploitation of this vulnerability could lead to privilege escalation, allowing an attacker to access and manipulate resources on a local server that are assumed to be safe due to network segmentation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.