puppeteer@1.2.0 vulnerabilities

A high-level API to control headless Chrome over the DevTools Protocol

  • latest version

    23.10.3

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    20 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the puppeteer package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Use After Free

    puppeteer is a Node library which provides a high-level API to control Chrome or Chromium over the DevTools Protocol.

    Affected versions of this package are vulnerable to Use After Free via the Chromium FileReader.

    Note: This vulnerability affects all software based on Chromium, including Electron.

    How to fix Use After Free?

    Upgrade puppeteer to version 1.13.0 or higher.

    <1.13.0