CVE-2024-39919
JavaScript vulnerability analysis and mitigation

Overview

@jmondi/url-to-png is an open source URL to PNG utility featuring parallel rendering using Playwright for screenshots and with storage caching via Local, S3, or CouchDB. The vulnerability was discovered in versions prior to 2.1.1, where the package includes an ALLOW_LIST functionality that by default permits capturing screenshots of web services running on localhost, 127.0.0.1, or the [::]. This vulnerability was assigned CVE-2024-39919 and was disclosed on July 15, 2024 (GitHub Advisory).

Technical details

The vulnerability stems from the package's default configuration which allows capturing screenshots of web services running on localhost addresses. The package includes an ALLOW_LIST feature where hosts can specify permitted services for screenshot capture, but by default, it allows access to localhost (127.0.0.1) and [::] addresses. The vulnerability has been assigned a CVSS v3.1 score of 3.1 (LOW) with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

If the package is hosted on a server, unauthorized users could potentially capture screenshots of other web services running locally on that server, potentially exposing sensitive information from internal web services that are not intended for public access (GitHub Advisory).

Exploitability

The vulnerability can be exploited by sending requests to capture screenshots using localhost URLs in various formats: http://[::]:port, http://localhost:port, or http://127.0.0.1:port. A proof of concept demonstrates that an attacker can capture screenshots of private local services running on different ports (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been addressed in version 2.1.1 with the addition of a blocklist feature. Users are advised to upgrade to this version. The fix implements a BLOCK_LIST environment variable that can be used to specify domains that should be blocked from screenshot capture (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54155HIGH7.7
  • JavaScript logoJavaScript
  • node-opcua
NoNoAug 20, 2026
CVE-2026-54156HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 20, 2026
CVE-2026-55451MEDIUM6.9
  • JavaScript logoJavaScript
  • gettext-converter
NoYesAug 20, 2026
CVE-2026-54150MEDIUM6.9
  • JavaScript logoJavaScript
  • next-video
NoYesAug 20, 2026
GHSA-ghvf-qf6h-g8x5HIGHN/A
  • JavaScript logoJavaScript
  • @nocobase/server
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management