GHSA-c2gp-86p4-5935
GitHub Security Advisory
Use-After-Free in puppeteer
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Versions of `puppeteer` prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.
## Recommendation
Upgrade to version 1.13.0 or later.
Affected Packages
npm
puppeteer
Affected versions:
0
(fixed in 1.13.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 13, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.