CVE-2024-36527
28Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 6.5epss 2.6%
exploitation probability
2.6%top 15% of all CVEs
observed exploitation
nono source reports it
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a