Versions of puppeteer
prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.
Upgrade to version 1.13.0 or later.
blog.exodusintel.com/2019/03/20/cve-2019-5786-analysis-and-exploitation
chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html
crbug.com/936448
github.com/GoogleChrome/puppeteer
github.com/GoogleChrome/puppeteer/issues/4141
nvd.nist.gov/vuln/detail/CVE-2019-5786
snyk.io/vuln/SNYK-JS-PUPPETEER-174321
www.npmjs.com/advisories/824