Server-Side Request Forgery Vulnerability in PlaywrightCapture Plugin by Lookyloo
CVE-2026-44439

6.6MEDIUM

Key Information:

Vendor

Lookyloo

Vendor
CVE Published:
13 May 2026

What is CVE-2026-44439?

PlaywrightCapture, a simple replacement for splash using Playwright, prior to version 1.39.6, has a vulnerability that fails to adequately limit navigations and resource requests initiated by external pages. This flaw allows an attacker to exploit browser-side redirection mechanisms like window.location.href, leading to potential exposure of sensitive internal resources or local file access. In scenarios where untrusted URLs are processed, attackers could leverage this vulnerability to perform SSRF attacks against internal services. Depending on the artifacts produced by the capture process (such as screenshots, saved content, logs), confidential information may be unintentionally disclosed, heightening security risks.

Affected Version(s)

PlaywrightCapture < 1.39.6

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.