CVE-2020-15660: Mozilla Geckodriver
High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
Affected products
- Mozilla Geckodriver: before 0.27.0 (fixed in 0.27.0)
Published 2021-07-20. Last modified 2026-06-17.