CVE-2026-73210
- EPSS 0.42%
- Veröffentlicht 11.08.2026 13:59:51
- Zuletzt bearbeitet 12.08.2026 19:17:54
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-...
CVE-2026-63175
- EPSS 0.3%
- Veröffentlicht 15.07.2026 21:26:26
- Zuletzt bearbeitet 16.07.2026 14:16:56
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including...
CVE-2026-44439
- EPSS 0.32%
- Veröffentlicht 13.05.2026 21:29:24
- Zuletzt bearbeitet 28.05.2026 17:37:08
PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-sid...