Protection Mechanism Failure Affecting chrome-devtools-frontend package, versions <1.0.1510180


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-CHROMEDEVTOOLSFRONTEND-14038289
  • published16 Nov 2025
  • disclosed14 Nov 2025
  • creditAlesandro Ortiz, Daniel Fröjdendahl

Introduced: 14 Nov 2025

NewCVE-2025-13097  (opens in a new tab)
CWE-693  (opens in a new tab)

How to fix?

Upgrade chrome-devtools-frontend to version 1.0.1510180 or higher.

Overview

chrome-devtools-frontend is a Chrome DevTools UI

Affected versions of this package are vulnerable to Protection Mechanism Failure through the openInNewTab() function in the InspectorFrontendHostStub class within Chrome's DevTools component. An attacker can perform a sandbox escape by crafting an HTML page that passes a javascript: URL scheme to the openInNewTab() method, which does not validate URL schemes before opening them in a new tab.

CVSS Base Scores

version 4.0
version 3.1