📡 GitHub-Advisory · 2026-05-06
CVE-2026-44439 - Playwright Capture permits access to local files and internal network resources
CVE-2026-44439
GHSA-687h-xw6f-q2qw MEDIUM pip/PlaywrightCapture
CVE: CVE-2026-44439
Playwright Capture did not sufficiently restrict navigations and resource requests initiated by rendered pages. An attacker-controlled page could abuse browser-side redirection mechanisms, such as window.location.href, to