PT-2026-70210 · Lookyloo · Playwrightcapture
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Lookyloo PlaywrightCapture (affected versions not specified)
Description
A Server-Side Request Forgery (SSRF) issue occurs when the
only global lookup option is enabled. While this option is intended to block access to local, loopback, or non-public network resources, the favicon retrieval process bypasses these protections. Favicon URLs extracted from HTML are fetched directly using an aiohttp.ClientSession without proper validation. An attacker controlling a processed web page can use a crafted favicon reference to force the host to make HTTP requests to internal network services, private IP addresses, or loopback addresses. This can lead to internal service discovery or unauthorized interaction with internal HTTP endpoints.Recommendations
Apply the patch that introduces a common URL validation routine to favicon retrieval to reject non-global IP addresses, localhost, .local domains, and malformed URLs.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Playwrightcapture