Low severity3.5NVD Advisory· Published Feb 23, 2021· Updated Jun 17, 2026
CVE-2020-8902
CVE-2020-8902
Description
Rendertron versions prior to 3.0.0 are are susceptible to a Server-Side Request Forgery (SSRF) attack. An attacker can use a specially crafted webpage to force a rendertron headless chrome process to render internal sites it has access to, and display it as a screenshot. Suggested mitigations are to upgrade your rendertron to version 3.0.0, or, if you cannot update, to secure the infrastructure to limit the headless chrome's access to your internal domain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rendertronnpm | < 3.0.0 | 3.0.0 |
Affected products
2- Google LLC/Rendertronv5Range: stable
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.