VendorsMozillageckodriverany version
Vulnerabilities

Mozilla geckodriver any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2020-15660
Missing checks on Content-Type headers in geckodriver before 0.27.0 could lead to a CSRF vulnerability, that might, when paired with a specifically prepared request, lead to remote code execution.
Published 2021-07-20 · Modified
8.8EPSS 0.011
CVE-2021-4138
Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.
Published 2022-05-02 · Modified
5.3EPSS 0.008