Description
Use of curl with the -k (or --insecure) flag in installer scripts allows attackers to deliver arbitrary executables via Man-in-the-Middle (MitM) attacks. This can lead to full system compromise, as the downloaded files are installed as privileged applications.
Recommendation
Update the playwright package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.55.1
- Patched version(s): 1.55.1
References
Could your website be exposed too?
SmartScanner can check your website for Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate and gives you actionable findings to investigate.
Start a free scanRelated Issues
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/react-router - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nuxt - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/nextjs - CVE-2025-53548
- @clerk/backend Performs Insufficient Verification of Data Authenticity - @clerk/backend - CVE-2025-53548


