CVE-2023-38695
04.08.2023, 18:15
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
Vendor | Product | Version |
---|---|---|
simonsmith | cypress_image_snapshot | 𝑥 < 8.0.2 |
𝑥
= Vulnerable software versions