{"id":"GHSA-665w-mwrr-77q3","summary":"Arbitrary file read via Playwright's screenshot feature exploiting file wrapper","details":"### Impact\n\nAll users of url-to-png. Please see https://github.com/jasonraimondi/url-to-png/issues/47\n\n### Patches\n\n[v2.0.3](https://github.com/jasonraimondi/url-to-png/releases/tag/v2.0.3) requires input url to be of protocol `http` or `https` \n\n### Workarounds\n\nRequires upgrade.\n\n### References\n\n- https://github.com/jasonraimondi/url-to-png/issues/47\n- https://github.com/user-attachments/files/15536336/Arbitrary.File.Read.via.Playwright.s.Screenshot.Feature.Exploiting.File.Wrapper.pdf\n","aliases":["CVE-2024-37169"],"modified":"2026-09-10T03:50:14.979126354Z","published":"2024-06-05T13:29:10Z","database_specific":{"nvd_published_at":"2024-06-10T22:15:12Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-06-05T13:29:10Z"},"references":[{"type":"WEB","url":"https://github.com/jasonraimondi/url-to-png/security/advisories/GHSA-665w-mwrr-77q3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37169"},{"type":"WEB","url":"https://github.com/jasonraimondi/url-to-png/issues/47"},{"type":"WEB","url":"https://github.com/jasonraimondi/url-to-png/commit/9336020c5e603323f5cf4a2ac3bb9a7735cf61f7"},{"type":"PACKAGE","url":"https://github.com/jasonraimondi/url-to-png"},{"type":"WEB","url":"https://github.com/jasonraimondi/url-to-png/releases/tag/v2.0.3"},{"type":"WEB","url":"https://github.com/user-attachments/files/15536336/Arbitrary.File.Read.via.Playwright.s.Screenshot.Feature.Exploiting.File.Wrapper.pdf"}],"affected":[{"package":{"name":"@jmondi/url-to-png","ecosystem":"npm","purl":"pkg:npm/%40jmondi/url-to-png"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-665w-mwrr-77q3/GHSA-665w-mwrr-77q3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}