Server-Side Request Forgery Vulnerability in PlaywrightCapture Plugin by Lookyloo
CVE-2026-44439
What is CVE-2026-44439?
PlaywrightCapture, a simple replacement for splash using Playwright, prior to version 1.39.6, has a vulnerability that fails to adequately limit navigations and resource requests initiated by external pages. This flaw allows an attacker to exploit browser-side redirection mechanisms like window.location.href, leading to potential exposure of sensitive internal resources or local file access. In scenarios where untrusted URLs are processed, attackers could leverage this vulnerability to perform SSRF attacks against internal services. Depending on the artifacts produced by the capture process (such as screenshots, saved content, logs), confidential information may be unintentionally disclosed, heightening security risks.
Affected Version(s)
PlaywrightCapture < 1.39.6
