Junglewise Threat Intelligence

CVE-2025-59288: Microsoft Playwright unverified SSL certificate in browser installation

CVE-2025-59288 · Severity: medium · CVSS 4 · Published 2025-10-14

Vendors: Microsoft, npm.

Executive brief

Playwright is a framework developers use to automate browser testing and web scraping. The installation scripts for browser packages use curl with SSL certificate verification disabled, allowing an attacker on the network to intercept downloads and inject malicious code that runs with system administrator privileges. This can lead to complete system compromise, especially in shared CI/CD environments.

Technical details

The vulnerability is an improper certificate validation issue (CWE-295) in Playwright's macOS browser installer shell scripts. The scripts use `curl -k` (insecure flag) to download browser packages and immediately install them with `sudo`, disabling SSL/TLS verification. An attacker positioned on the network can perform a man-in-the-middle attack to intercept HTTPS requests and serve malicious installer packages. No user authentication or special preconditions are required beyond running the script on a hostile network. Successful exploitation results in arbitrary code execution with root/administrator privileges. The fix was patched in version 1.56.0 via removal of the `-k` flag and proper certificate validation.

Affected products

  • Microsoft Playwright before 1.56.0

Timeline

  • 2025-10-14: disclosed: Public disclosure via GitHub Advisory GHSA-7mvr-c777-76hp
  • 2025-10-06: patched: Fix released in version 1.56.0
  • 2025-09-10: other: Initially reported to Microsoft privately

References