
Cloud Vulnerability DB
A community-led vulnerabilities database
@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. A path traversal vulnerability was discovered in versions prior to 2.1.2, where the ImageId input in the code was not properly sanitized (GitHub Advisory).
The vulnerability stems from insufficient sanitization of the ImageId parameter in extract_query_params.ts. The issue occurs when the imageId is constructed using unsanitized parameters via 'configToString(params)', which when combined with the storage path in filesystem.ts could lead to path traversal. The vulnerability has been assigned a CVSS v3.1 score of 4.3 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N (NVD).
The vulnerability allows an attacker to store an image in an arbitrary location that the server has permission to access. This could potentially lead to unauthorized file writes in unintended locations on the system (GitHub Advisory).
The vulnerability can be exploited by manipulating query parameters in the URL. For example, using parameters like '../../../../../../../../../../../../tmp/hack' in the URL can cause files to be written to unintended locations like the /tmp directory (GitHub Advisory).
The vulnerability has been patched in version 2.1.2. The fix involves properly sanitizing the parameters using the slugify function. Users are advised to upgrade to this version. There are no known workarounds for this vulnerability (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."