Junglewise Threat Intelligence

CVE-2023-38695: simonsmith cypress-image-snapshot path traversal in snapshot file names

CVE-2023-38695 · Severity: low · CVSS 3.1 · Published 2023-08-01

Vendors: npm.

Executive brief

cypress-image-snapshot is a testing utility for Cypress that captures and compares image snapshots during automated tests. A path traversal flaw allows an attacker to write snapshot files outside the intended project directory, potentially overwriting arbitrary files on the machine running tests and compromising test integrity or system stability.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the matchImageSnapshot() function that fails to sanitize user-supplied snapshot file names. An attacker can pass relative path sequences (e.g., '../../../') as the snapshot name parameter to escape the intended snapshot directory and write files to arbitrary locations accessible to the test runner process. This requires the attacker to control the argument passed to matchImageSnapshot(), which could occur if test parameters come from untrusted input. The vulnerability is fixed in version 8.0.2.

Affected products

  • simonsmith cypress-image-snapshot <= 8.0.1

Timeline

  • 2023-08-01: disclosed: Published on GitHub advisory database
  • 2023-08-01: patched: Fixed in version 8.0.2

References