Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63175— Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture

AI Predicted 6.5 Difficulty: Moderate EPSS 0.29% · P22

Affected Version Matrix 1

VendorProductVersion RangeStatus
LookylooPlaywrightCapture≤ v1.40.2affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-63175

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture
Source: CVE Program / CVE List V5
Vulnerability Description
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies, browser storage, HTTP credentials, proxy configuration, user-agent settings, geolocation information, and captured request data. In a multi-user or concurrent deployment, information supplied during one capture could therefore persist and be reused by a subsequent or parallel capture. This could result in the disclosure of authentication cookies, credentials, browser storage, or captured request data belonging to another user. It could also cause requests to be performed with another capture's authentication context, headers, or proxy configuration, potentially enabling unauthorized access to remote resources or interference with other capture operations. The vulnerability is resolved by initializing all capture-specific settings and request data as instance variables in the Capture constructor, ensuring that state is isolated between capture operations.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的会话过期机制
Source: CVE Program / CVE List V5
Vulnerability Title
Lookyloo PlaywrightCapture 会话机制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Lookyloo PlaywrightCapture是Lookyloo的网页截图捕获工具。 Lookyloo PlaywrightCapture v1.40.2及之前版本存在会话机制问题漏洞,该漏洞源于将捕获特定配置和运行时数据存储为可变的类级变量而非实例级变量,导致在同一个Python进程中运行的多个Capture对象可能共享状态,包括HTTP标头、cookie、浏览器存储、HTTP凭据、代理配置、用户代理设置、地理位置信息和捕获的请求数据,在多用户或并发部署中可能导致身份验证cookie、凭据、浏览器
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LookylooPlaywrightCapture 0 ~ v1.40.2 -

II. Public POCs for CVE-2026-63175

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63175

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-63175

No comments yet


Leave a comment