Vulnerabilities/

chromedriver Command Injection vulnerability

Severity:
Medium

Description

Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system.

Recommendation

Update the chromedriver package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
chromedriver
Anything's wrong? Let us know Last updated on November 17, 2023

This issue is available in SmartScanner Professional

See Pricing