GHSA-8p9r-f949-699g
Dashboard / Vulnerabilities / GHSA-8p9r-f949-699g
GHSA-8p9r-f949-699g
Summary: Path Traversal in browserless-chrome
Details: This affects all versions of browserless-chrome before 1.43.0. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-7758, https://github.com/browserless/chrome/commit/848b87e5bea4f8473eea85261a5ff922d6ebd2b6, https://github.com/browserless/chrome, https://github.com/browserless/chrome/blob/master/src/routes.ts%23L175, https://github.com/browserless/chrome/releases/tag/1.40.2-chrome-stable, https://snyk.io/vuln/SNYK-JS-BROWSERLESSCHROME-1023657, https://www.npmjs.com/package/browserless-chrome
Affected packages
Package
Name: browserless-chrome
Purl: pkg:npm/browserless-chrome
Affected ranges
Type: SEMVER
Events:
