CVE-2024-39918
JavaScript vulnerability analysis and mitigation

Overview

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. A path traversal vulnerability was discovered in versions prior to 2.1.2, where the ImageId input in the code was not properly sanitized (GitHub Advisory).

Technical details

The vulnerability stems from insufficient sanitization of the ImageId parameter in extract_query_params.ts. The issue occurs when the imageId is constructed using unsanitized parameters via 'configToString(params)', which when combined with the storage path in filesystem.ts could lead to path traversal. The vulnerability has been assigned a CVSS v3.1 score of 4.3 (Medium) with vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N (NVD).

Impact

The vulnerability allows an attacker to store an image in an arbitrary location that the server has permission to access. This could potentially lead to unauthorized file writes in unintended locations on the system (GitHub Advisory).

Exploitability

The vulnerability can be exploited by manipulating query parameters in the URL. For example, using parameters like '../../../../../../../../../../../../tmp/hack' in the URL can cause files to be written to unintended locations like the /tmp directory (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 2.1.2. The fix involves properly sanitizing the parameters using the slugify function. Users are advised to upgrade to this version. There are no known workarounds for this vulnerability (NVD).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77415CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77414CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77413CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-63421HIGH7.5
  • JavaScript logoJavaScript
  • @keystone-6/core
NoYesAug 21, 2026
CVE-2026-53509MEDIUM5.7
  • JavaScript logoJavaScript
  • @aborruso/ckan-mcp-server
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management