LOW3.7npm
GHSA-342q-2mc2-5gmp· CVE-2024-39919@jmondi/url-to-png enables capture screenshot of localhost web services (unauthenticated pages)
Modified: 9/10/2026
package
pkg:npm/%40jmondi/url-to-png
@jmondi/url-to-png enables capture screenshot of localhost web services (unauthenticated pages)
Modified: 9/10/2026
Arbitrary file read via Playwright's screenshot feature exploiting file wrapper
Modified: 9/10/2026
@jmondi/url-to-png contains a Path Traversal vulnerability
Modified: 9/10/2026