Skip to content

Update dependency playwright to v1.55.1 [SECURITY] - #467

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-playwright-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-playwright-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 20, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
playwright (source) 1.53.2 → 1.55.1 age confidence
playwright (source) 1.53.1 → 1.55.1 age confidence

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

CVE-2025-59288 / GHSA-7mvr-c777-76hp

More information

Details

Summary

Use of curl with the -k (or --insecure) flag in installer scripts allows attackers to deliver arbitrary executables via Man-in-the-Middle (MitM) attacks. This can lead to full system compromise, as the downloaded files are installed as privileged applications.

Details

The following scripts in the microsoft/playwright repository at commit bee11cbc28f24bd18e726163d0b9b1571b4f26a8 use curl -k to fetch and install executable packages without verifying the authenticity of the SSL certificate:

In each case, the shell scripts download a browser installer package using curl -k and immediately install it:

curl --retry 3 -o ./<pkg-file> -k <url>
sudo installer -pkg /tmp/<pkg-file> -target /

Disabling SSL verification (-k) means the download can be intercepted and replaced with malicious content.

PoC

A high-level exploitation scenario:

  1. An attacker performs a MitM attack on a network where the victim runs one of these scripts.
  2. The attacker intercepts the HTTPS request and serves a malicious package (for example, a trojaned browser installer).
  3. Because curl -k is used, the script downloads and installs the attacker's payload without any certificate validation.
  4. The attacker's code is executed with system privileges, leading to full compromise.

No special configuration is needed: simply running these scripts on any untrusted or hostile network is enough.

Impact

This is a critical Remote Code Execution (RCE) vulnerability due to improper SSL certificate validation (CWE-295: Improper Certificate Validation). Any user or automation running these scripts is at risk of arbitrary code execution as root/admin, system compromise, data theft, or persistent malware installation. The risk is especially severe because browser packages are installed with elevated privileges and the scripts may be used in CI/CD or developer environments.

Fix
Credit
  • This vulnerability was uncovered by tooling by Socket
  • This vulnerability was confirmed by @​evilpacket
  • This vulnerability was reported by @​JLLeitschuh at Socket
Disclosure

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

microsoft/playwright (playwright)

v1.55.1

Compare Source

Highlights

#​37479 - [Bug]: Upgrade Chromium to 140.0.7339.186.
#​37147 - [Regression]: Internal error: step id not found.
#​37146 - [Regression]: HTML reporter displays a broken chip link when there are no projects.
#​37137 - Revert "fix(a11y): track inert elements as hidden".
#​37532 - chore: do not use -k option

Browser Versions

  • Chromium 140.0.7339.186
  • Mozilla Firefox 141.0
  • WebKit 26.0

This version was also tested against the following stable channels:

  • Google Chrome 139
  • Microsoft Edge 139

v1.55.0

Compare Source

New APIs

  • New Property testStepInfo.titlePath Returns the full title path starting from the test file, including test and step titles.

Codegen

  • Automatic toBeVisible() assertions: Codegen can now generate automatic toBeVisible() assertions for common UI interactions. This feature can be enabled in the Codegen settings UI.

Breaking Changes

  • ⚠️ Dropped support for Chromium extension manifest v2.

Miscellaneous

  • Added support for Debian 13 "Trixie".

Browser Versions

  • Chromium 140.0.7339.16
  • Mozilla Firefox 141.0
  • WebKit 26.0

This version was also tested against the following stable channels:

  • Google Chrome 139
  • Microsoft Edge 139

v1.54.2

Compare Source

Highlights

#​36714 - [Regression]: Codegen is not able to launch in Administrator Terminal on Windows (ProtocolError: Protocol error)
#​36828 - [Regression]: Playwright Codegen keeps spamming with selected option
#​36810 - [Regression]: Starting Codegen with target language doesn't work anymore

Browser Versions

  • Chromium 139.0.7258.5
  • Mozilla Firefox 140.0.2
  • WebKit 26.0

This version was also tested against the following stable channels:

  • Google Chrome 140
  • Microsoft Edge 140

v1.54.1

Compare Source

Highlights

#​36650 - [Regression]: 1.54.0 breaks downloading browsers when an HTTP(S) proxy is used

Browser Versions

  • Chromium 139.0.7258.5
  • Mozilla Firefox 140.0.2
  • WebKit 26.0

This version was also tested against the following stable channels:

  • Google Chrome 140
  • Microsoft Edge 140

v1.54.0

Compare Source

Highlights

  • New cookie property partitionKey in browserContext.cookies() and browserContext.addCookies(). This property allows to save and restore partitioned cookies. See CHIPS MDN article for more information. Note that browsers have different support and defaults for cookie partitioning.

  • New option noSnippets to disable code snippets in the html report.

    import { defineConfig } from '@playwright/test';
    
    export default defineConfig({
      reporter: [['html', { noSnippets: true }]]
    });
  • New property location in test annotations, for example in testResult.annotations and testInfo.annotations. It shows where the annotation like test.skip or test.fixme was added.

Command Line

  • New option --user-data-dir in multiple commands. You can specify the same user data dir to reuse browsing state, like authentication, between sessions.

    npx playwright codegen --user-data-dir=./user-data
  • Option -gv has been removed from the npx playwright test command. Use --grep-invert instead.

  • npx playwright open does not open the test recorder anymore. Use npx playwright codegen instead.

Miscellaneous

  • Support for Node.js 16 has been removed.
  • Support for Node.js 18 has been deprecated, and will be removed in the future.

Browser Versions

  • Chromium 139.0.7258.5
  • Mozilla Firefox 140.0.2
  • WebKit 26.0

This version was also tested against the following stable channels:

  • Google Chrome 140
  • Microsoft Edge 140

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Oct 20, 2025 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 23.60%. Comparing base (9433699) to head (6b2ad0b).
⚠️ Report is 13 commits behind head on main.

❗ There is a different number of reports uploaded between BASE (9433699) and HEAD (6b2ad0b). Click for more details.

HEAD has 2 uploads less than BASE
Flag BASE (9433699) HEAD (6b2ad0b)
3 1
Additional details and impacted files
@@             Coverage Diff             @@
##             main     #467       +/-   ##
===========================================
- Coverage   91.96%   23.60%   -68.37%     
===========================================
  Files          85       52       -33     
  Lines       47705    23045    -24660     
  Branches     5312       79     -5233     
===========================================
- Hits        43873     5440    -38433     
- Misses       3832    17605    +13773     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actions

github-actions Bot commented Oct 20, 2025 •

Copy link
Copy Markdown

Performance Report

✔️ no performance regression detected

Full benchmark results
Benchmark suite Current: 956b0f9 Previous: null Ratio
Création variable 188.80 ms/op
Ajouter nom variable 5.9405 ms/op
Création nuée 394.69 ms/op
Création bd 99.979 ms/op
Ajouter nom bd 4.0899 ms/op

by benchmarkbot/action

@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from bb0047a to 6b2ad0b Compare October 21, 2025 11:48
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 6b2ad0b to c297330 Compare October 29, 2025 07:52
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from c297330 to e2ace30 Compare November 10, 2025 20:01
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from e2ace30 to 90d6ada Compare November 18, 2025 22:29
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 90d6ada to 7704cf4 Compare December 3, 2025 18:31
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 7704cf4 to d2081ba Compare December 31, 2025 16:45
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from d2081ba to c355bb4 Compare January 8, 2026 16:27
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch 2 times, most recently from fca98cc to 5bcea14 Compare January 23, 2026 17:09
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 5bcea14 to 3144e6d Compare February 2, 2026 18:52
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch 2 times, most recently from 7b24c95 to 55a740b Compare February 17, 2026 14:10
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 55a740b to 410b2ba Compare March 5, 2026 19:01
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from 410b2ba to 423f72c Compare March 13, 2026 18:48
@renovate renovate Bot changed the title Update dependency playwright to v1.55.1 [SECURITY] Update dependency playwright to v1.55.1 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/npm-playwright-vulnerability branch March 27, 2026 02:09
@renovate renovate Bot changed the title Update dependency playwright to v1.55.1 [SECURITY] - autoclosed Update dependency playwright to v1.55.1 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch 3 times, most recently from c3ea793 to e3ebba4 Compare April 1, 2026 17:41
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from e3ebba4 to 1565408 Compare April 8, 2026 21:19
@renovate renovate Bot changed the title Update dependency playwright to v1.55.1 [SECURITY] Update dependency playwright to v1.55.1 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title Update dependency playwright to v1.55.1 [SECURITY] - autoclosed Update dependency playwright to v1.55.1 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from bea8e11 to 1565408 Compare April 27, 2026 23:34
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch 2 times, most recently from bea8e11 to d71124e Compare April 29, 2026 11:27
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from d71124e to 9d4d329 Compare May 7, 2026 13:19
@renovate

renovate Bot commented May 7, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update artifacts related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml
[WARN] The "pnpm" field in package.json is no longer read by pnpm. The following keys were ignored: "pnpm.onlyBuiltDependencies", "pnpm.overrides". See https://pnpm.io/settings for the new home of each setting.
Error: ERR_PNPM_MISSING_TARBALL_INTEGRITY

  × updating dependencies
  ╰─▶ 1 lockfile entries failed verification:
        xlsx@https://cdn.sheetjs.com/xlsx-0.19.1/xlsx-0.19.1.tgz has no
      "integrity" field, so its downloaded tarball cannot be verified
  help: The lockfile contains entries that the active policies reject. This
        can mean the lockfile is stale, or that someone committed a lockfile
        that bypassed the policy locally — inspect recent changes to pnpm-
        lock.yaml before trusting it. If the changes look expected, run "pnpm
        clean --lockfile" and then "pnpm install" to rebuild from a fresh
        resolution. Alternatively, relax the policy that flagged them.


File name: docu/scripts/images/pnpm-lock.yaml
Error: ERR_PNPM_EXOTIC_SUBDEP

  × updating dependencies
  ╰─▶ Failed to resolve dependency tree: Exotic dependency "iso-
      constants" (resolved via git-repository) is not allowed in
      subdependencies when blockExoticSubdeps is enabled


File name: docu/pnpm-lock.yaml
Error: ERR_PNPM_EXOTIC_SUBDEP

  × updating dependencies
  ╰─▶ Failed to resolve dependency tree: Exotic dependency "iso-
      constants" (resolved via git-repository) is not allowed in
      subdependencies when blockExoticSubdeps is enabled


@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch 2 times, most recently from 3c4ac2c to c31276a Compare May 12, 2026 11:42
@renovate
renovate Bot force-pushed the renovate/npm-playwright-vulnerability branch from c31276a to bd27e3f Compare May 18, 2026 10:01

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants