Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Timoxoszt

#48194of 53,624
5.3Total CVSS
Vulnerabilities · 1
PT-2024-27353
5.3
2024-06-05
Playright · Playright · CVE-2024-37169
**Name of the Vulnerable Software and Affected Versions** @jmondi/url-to-png versions prior to 2.0.3 **Description** The issue allows for arbitrary file read if a threat actor uses Playright's screenshot feature to exploit the file wrapper. No known workarounds are available aside from upgrading. The utility requires input URLs to be of protocol `http` or `https` to mitigate this issue. **Recommendations** For versions prior to 2.0.3, upgrade to version 2.0.3 or later, which requires input URLs to be of protocol `http` or `https`, to resolve the issue. As a temporary workaround, consider restricting the use of the Playright's screenshot feature until the upgrade is applied.