Executive brief
Puppeteer is a Node.js library used to automate browser testing and web scraping by controlling a Chromium instance. Versions prior to 1.13.0 contain a use-after-free vulnerability in Chromium's FileReader API that could allow an attacker to execute arbitrary code on a system running vulnerable Puppeteer.
Technical details
This is a use-after-free vulnerability (CWE-416) in Chromium's FileReader API that affects Puppeteer versions before 1.13.0. The vulnerability stems from improper memory management in the underlying Chromium engine. An attacker can trigger the use-after-free condition through crafted web content that interacts with the FileReader API, potentially achieving remote code execution. The attack requires user interaction (opening or processing malicious content in Puppeteer) but the network vector is available if Puppeteer processes untrusted URLs. A fix is available by upgrading to Puppeteer 1.13.0 or later.
Affected products
- Google Puppeteer < 1.13.0
Timeline
- 2020-09-02: disclosed
- 1.13.0: patched