CVE-2026-85242
- EPSS 0.25%
- Veröffentlicht 03.09.2026 16:17:20
- Zuletzt bearbeitet 08.09.2026 14:11:40
PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or...
CVE-2026-73210
- EPSS 0.42%
- Veröffentlicht 11.08.2026 13:59:51
- Zuletzt bearbeitet 26.08.2026 16:49:18
A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-...
CVE-2026-63175
- EPSS 0.3%
- Veröffentlicht 15.07.2026 21:26:26
- Zuletzt bearbeitet 16.07.2026 14:16:56
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including...
CVE-2026-44439
- EPSS 0.32%
- Veröffentlicht 13.05.2026 21:29:24
- Zuletzt bearbeitet 28.05.2026 17:37:08
PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-sid...