Lucene search

K
osvGoogleOSV:GHSA-C2GP-86P4-5935
HistorySep 02, 2020 - 6:25 p.m.

Use-After-Free in puppeteer

2020-09-0218:25:43
Google
osv.dev
57
puppeteer
use-after-free
vulnerability
upgrade
remote code execution
chromium
filereader api

EPSS

0.972

Percentile

99.9%

Versions of puppeteer prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.

Recommendation

Upgrade to version 1.13.0 or later.