PT-2026-70210 · Lookyloo · Playwrightcapture

·

CVE-2026-73210

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Lookyloo PlaywrightCapture (affected versions not specified)
Description A Server-Side Request Forgery (SSRF) issue occurs when the only global lookup option is enabled. While this option is intended to block access to local, loopback, or non-public network resources, the favicon retrieval process bypasses these protections. Favicon URLs extracted from HTML are fetched directly using an aiohttp.ClientSession without proper validation. An attacker controlling a processed web page can use a crafted favicon reference to force the host to make HTTP requests to internal network services, private IP addresses, or loopback addresses. This can lead to internal service discovery or unauthorized interaction with internal HTTP endpoints.
Recommendations Apply the patch that introduces a common URL validation routine to favicon retrieval to reject non-global IP addresses, localhost, .local domains, and malformed URLs.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73210

Affected Products

Playwrightcapture