Intel

AIKIDO-2026-10133

passbolt-browser-extension is vulnerable to Improper Restriction of Rendered UI Layers or Frames

Improper Restriction of Rendered UI Layers or Frames Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 9, 2026

64

Medium Risk

This Affects:

JSpassbolt-browser-extension
3.3.0 - 5.8.0
Fixed in 5.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow the in-form menu to be rendered without proper application context validation, enabling it to appear even when overlaid by other components. This could result in unintended UI exposure and interaction outside the intended application boundary. An attacker might exploit this by triggering the in-form menu in an overlaid or foreign application context to confuse users, intercept interactions, or facilitate phishing-like attacks by presenting trusted UI elements in an untrusted overlay.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

passbolt-browser-extension is vulnerable to Improper Restriction of Rendered UI Layers or Frames in versions 3.3.0 - 5.8.0.

How to fix this

Upgrade the passbolt-browser-extension library to the patch version.