@jmondi/url-to-png
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @jmondi/url-to-pngpage 1 of 1
- CVE-2024-37169MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.0.32024-06-10
@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Playright's screenshot feature to exploit the file wrapper. Version 2.0.3 mitigates this issue…
- CVE-2024-39918MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.1.22024-07-15
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. Input of the `ImageId` in the code is not sanitized and may lead to p…
- CVE-2024-39919LOWCVSS 3.1EG 3.1✓ Fixed in 2.1.22024-07-15
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. The package includes an `ALLOW_LIST` where the host can specify which…
Check whether @jmondi/url-to-png is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @jmondi/url-to-png CVEs against the assets you own.
Start Free Scan →