{"id":"CVE-2023-39015","details":"webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.","aliases":["GHSA-grvq-vjqr-x8vm"],"modified":"2026-08-12T03:51:44.524362521Z","published":"2023-07-28T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39015.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/39xxx/CVE-2023-39015.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39015"},{"type":"REPORT","url":"https://github.com/code4craft/webmagic/issues/1122"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/code4craft/webmagic","events":[{"introduced":"0"},{"last_affected":"fd4a136f9a583fbcf240b1d73103f9353391afb0"}],"database_specific":{"cpe":"cpe:2.3:a:code4craft:webmagic:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.0"}],"source":"CPE_RANGE"}}],"versions":["WebMagic-0.9.0","WebMagic-0.8.0","WebMagic-0.7.6","WebMagic-0.7.5","WebMagic-0.7.4","WebMagic-0.7.3","WebMagic-0.7.2","WebMagic-0.7.1","WebMagic-0.7.0","WebMagic-0.7.0.alpha","webmagic-parent-0.6.1","webmagic-parent-0.6.0","WebMagic-0.6.0","0.6.0","webmagic-0.5.3","WebMagic-0.5.2","WebMagic-0.5.1","WebMagic-0.5.0","webmaigc-0.4.3","webmagic-0.4.2","webmagic-0.4.1","webmagic-0.4.0","webmagic-0.3.2","webmagic-parent-0.3.1","webmagic-0.3.0","webmagic-parent-0.2.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39015.json"}}],"schema_version":"1.9.0"}