HIGH7.5CVE-2026-30834PinchTab has SSRF with Full Response Exfiltration via Download Handler in github.com/pinchtab/pinchtab
from 0, < 0.7.7
MEDIUM6.7CVE-2026-33623PinchTab: OS Command Injection via Profile Name in Windows Cleanup Routine Enables Arbitrary Command Execution in github.com/pinchtab/pinchtab
from 0, < 0.8.5
—CVE-2026-33622A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution in github.com/pinchtab/pinchtab