2024-06-22 09:37:59 +00:00
### [CVE-2024-36527](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36527)



### Description
puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
### POC
#### Reference
2024-07-25 21:25:12 +00:00
- https://gist.github.com/7a6163/25fef08f75eed219c8ca21e332d6e911
2024-06-22 09:37:59 +00:00
#### Github
- https://github.com/nomi-sec/PoC-in-GitHub