Executive brief
PlaywrightCapture is a tool used to automate the process of capturing and rendering web pages. A security flaw allows an attacker to trick the tool into accessing private internal network resources or local files on the server instead of the intended public website. This could lead to the exposure of sensitive internal data, such as configuration files or private service responses, through the tool's screenshots and logs.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in PlaywrightCapture due to insufficient restriction of navigations and resource requests initiated by rendered pages. An attacker can provide a malicious URL that uses browser-side redirection (e.g., window.location.href) to force the capture process to access file:// URLs or non-public IP addresses (loopback, private, or link-local). This allows for the exfiltration of local files or internal service responses through capture artifacts like screenshots, saved page content, or logs. The issue is addressed in version 1.39.6 by implementing request routing checks that block secondary requests to non-global IP addresses and local domains when the only_global_lookup setting is enabled.
Affected products
- Lookyloo PlaywrightCapture < 1.39.6
Timeline
- 2026-04-30: disclosed: Vulnerability reported to vendor
- 2026-05-06: advisory: GitHub Advisory published
- 2026-05-13: other: NVD published CVE-2026-44439