CVE-2023-38695

MEDIUM

cypress-image-snapshot <8.0.2 - Path Traversal

Title source: llm
STIX 2.1

Description

cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.

Scores

CVSS v3 6.5
EPSS 0.0080
EPSS Percentile 51.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
simonsmith/cypress-image-snapshot 0 - 8.0.2npm
simonsmith/cypress_image_snapshot < 8.0.2
Published Aug 04, 2023
Tracked Since Feb 18, 2026