CVE-2023-38695: Simonsmith Cypress Image Snapshot
Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.
cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.
Affected products
- Simonsmith Cypress Image Snapshot: before 8.0.2 (fixed in 8.0.2)
Published 2023-08-04. Last modified 2026-06-17.