GHSA-vxjg-hchx-cc4g
@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names
Quick fix
GHSA-vxjg-hchx-cc4g — @simonsmith/cypress-image-snapshot: upgrade to the fixed version with the command below.
npm install @simonsmith/cypress-image-snapshot@8.0.2Details
### Impact It's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. Example:
```js cy.get('h1').matchImageSnapshot('../../../ignore-relative-dirs') ``` The above will create an `ignore-relative-dirs.png` three levels up
### Patches Fixed in `8.0.2`
### Workarounds Validate all the existing uses of `matchImageSnapshot` to ensure correct use of the filename argument. Example:
```js // snapshot name will be the test title cy.matchImageSnapshot();
// snapshot name will be the name passed in cy.matchImageSnapshot('login'); ```
### References https://github.com/simonsmith/cypress-image-snapshot/issues/15
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 8.0.2npm install @simonsmith/cypress-image-snapshot@8.0.2References
- https://github.com/simonsmith/cypress-image-snapshot/security/advisories/GHSA-vxjg-hchx-cc4g[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-38695[ADVISORY]
- https://github.com/simonsmith/cypress-image-snapshot/issues/15[WEB]
- https://github.com/simonsmith/cypress-image-snapshot/commit/ef49519795daf5183f4fac6f3136e194f20f39f4[WEB]
- https://github.com/simonsmith/cypress-image-snapshot[PACKAGE]
- https://github.com/simonsmith/cypress-image-snapshot/releases/tag/8.0.2[WEB]