puppeteer-renderer v.3.2.0 and before is vulnerable to Directory Traversal. Attackers can exploit the URL parameter using the file protocol to read sensitive information from the server.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view