puppeteer@1.7.0-next.1536177940806 vulnerabilities

A high-level API to control headless Chrome over the DevTools Protocol

  • latest version

    24.26.1

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the puppeteer package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Use After Free

    puppeteer is a Node library which provides a high-level API to control Chrome or Chromium over the DevTools Protocol.

    Affected versions of this package are vulnerable to Use After Free via the Chromium FileReader.

    Note: This vulnerability affects all software based on Chromium, including Electron.

    How to fix Use After Free?

    Upgrade puppeteer to version 1.13.0 or higher.

    <1.13.0