Executive brief
PlaywrightCapture is a web scraping tool that captures screenshots and data from web pages. It contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval feature: when processing a web page, an attacker can craft a favicon URL that redirects to internal services (like localhost or private IP addresses), bypassing the application's network access restrictions. This could allow probing of internal services or unauthorized information disclosure.
Technical details
PlaywrightCapture implements local-address validation for favicon URLs when only_global_lookup is enabled, blocking requests to localhost, loopback addresses, and internal IP ranges. However, the validation was not applied to HTTP redirects followed by the aiohttp library, allowing an attacker to specify a publicly reachable favicon URL that redirects to a restricted address, bypassing the filter. The vulnerability requires the attacker to influence page content processed by PlaywrightCapture and depends on internal services being accessible from the host. The patch introduces aiohttp middleware that validates every request in the redirect chain before it is issued, preventing requests to local or restricted destinations.
Affected products
- Lookyloo PlaywrightCapture <b912a04
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Fix applied in commit b912a04f7b190807b5e14e497048896bc5016fb9