QID 982616
QID 982616: Nodejs (npm) Security Update for browserless-chrome (GHSA-8p9r-f949-699g)
This affects all versions of browserless-chrome before 1.43.0. User input flowing from the workspace endpoint gets used to create a file path filePath and this is fetched and then sent back to a user. This can be escaped to fetch arbitrary files from a server.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8p9r-f949-699g for updates pertaining to this vulnerability.
Vendor References
- GHSA-8p9r-f949-699g -
github.com/advisories/GHSA-8p9r-f949-699g
CVEs related to QID 982616
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8p9r-f949-699g | browserless-chrome |
|