Insufficient Session Expiration Affecting playwrightcapture package, versions [,1.40.3)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.3% (22nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PLAYWRIGHTCAPTURE-18017912
  • published19 Jul 2026
  • disclosed16 Jul 2026
  • creditUnknown

Introduced: 16 Jul 2026

NewCVE-2026-63175  (opens in a new tab)
CWE-613  (opens in a new tab)

How to fix?

Upgrade PlaywrightCapture to version 1.40.3 or higher.

Overview

PlaywrightCapture is an A simple library to capture websites using playwright

Affected versions of this package are vulnerable to Insufficient Session Expiration due to the use of mutable class-level variables for capture-specific configuration and runtime data instead of instance-level variables. An attacker can access or interfere with another user's session data, such as HTTP headers, cookies, credentials, browser storage, proxy configuration, and captured request data, by initiating concurrent or subsequent capture operations within the same process.

References

CVSS Base Scores

version 4.0
version 3.1