{"schema_version":"1.9.0","id":"GHSA-c2gp-86p4-5935","published":"2020-09-02T18:25:43Z","modified":"2023-11-08T04:01:37.201603Z","aliases":["CVE-2019-5786"],"summary":"Use-After-Free in puppeteer","details":"Versions of `puppeteer` prior to 1.13.0 are vulnerable to the Use-After-Free vulnerability in Chromium (CVE-2019-5786). The Chromium FileReader API is vulnerable to Use-After-Free which may lead to Remote Code Execution.\n\n\n## Recommendation\n\nUpgrade to version 1.13.0 or later.","affected":[{"package":{"name":"puppeteer","ecosystem":"npm","purl":"pkg:npm/puppeteer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-c2gp-86p4-5935/GHSA-c2gp-86p4-5935.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-5786"},{"type":"WEB","url":"https://github.com/GoogleChrome/puppeteer/issues/4141"},{"type":"WEB","url":"https://blog.exodusintel.com/2019/03/20/cve-2019-5786-analysis-and-exploitation"},{"type":"WEB","url":"https://chromereleases.googleblog.com/2019/03/stable-channel-update-for-desktop.html"},{"type":"WEB","url":"https://crbug.com/936448"},{"type":"PACKAGE","url":"https://github.com/GoogleChrome/puppeteer"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-PUPPETEER-174321"},{"type":"WEB","url":"https://www.npmjs.com/advisories/824"}],"database_specific":{"cwe_ids":["CWE-416"],"github_reviewed":true,"github_reviewed_at":"2020-08-31T18:37:09Z","nvd_published_at":"2019-06-27T17:15:13Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}