VDB
Sign up
MEDIUM6.5

GHSA-vxjg-hchx-cc4g

@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names

Quick fix

GHSA-vxjg-hchx-cc4g — @simonsmith/cypress-image-snapshot: upgrade to the fixed version with the command below.

npm install @simonsmith/cypress-image-snapshot@8.0.2

Details

### Impact It's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. Example:

```js cy.get('h1').matchImageSnapshot('../../../ignore-relative-dirs') ``` The above will create an `ignore-relative-dirs.png` three levels up

### Patches Fixed in `8.0.2`

### Workarounds Validate all the existing uses of `matchImageSnapshot` to ensure correct use of the filename argument. Example:

```js // snapshot name will be the test title cy.matchImageSnapshot();

// snapshot name will be the name passed in cy.matchImageSnapshot('login'); ```

### References https://github.com/simonsmith/cypress-image-snapshot/issues/15

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@simonsmith/cypress-image-snapshot
Introduced in: 0Fixed in: 8.0.2
Fixnpm install @simonsmith/cypress-image-snapshot@8.0.2

References