VYPR

npm package

alto-saxophone

pkg:npm/alto-saxophone

Vulnerabilities (1)

  • CVE-2016-10694Jun 4, 2018
    affected < 2.25.1fixed 2.25.1

    alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out t