VDB
Sign up
MEDIUM6.5

GHSA-c2gp-86p4-5935

Use-After-Free in puppeteer

Quick fix

GHSA-c2gp-86p4-5935 — puppeteer: upgrade to the fixed version with the command below.

npm install puppeteer@1.13.0

Details

Versions of `puppeteer` prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.

## Recommendation

Upgrade to version 1.13.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/puppeteer
Introduced in: 0Fixed in: 1.13.0
Fixnpm install puppeteer@1.13.0

References