Description
Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unauthorized access and potentially malicious actions on the host system.
Recommendation
Update the chromedriver package to the latest compatible version. Followings are version details:
- Affected version(s): < 119.0.1
- Patched version(s): 119.0.1
References
Related Issues
- automagik-genie has a command injection vulnerability - CVE-2026-30635
- Nadesiko3 OS Command Injection vulnerability - CVE-2022-41642
- A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA - CVE-2023-33831
- matrix-appservice-irc IRC command injection via admin commands containing newlines - CVE-2023-38690
You might also like:
- Tags:
- npm
- chromedriver
Anything's wrong? Let us know Last updated on November 17, 2023


