Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59288

20
FAUCET Score

CVE-2025-59288 is a medium-severity vulnerability affecting Microsoft Playwright, stemming from improper cryptographic signature verification. An attacker on an adjacent network can exploit this with high attack complexity to achieve high confidentiality impact through spoofing, without requiring user interaction or privileges. While not currently in the KEV catalog and lacking public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.55.1CPE matchmatch criteria
cpe:2.3:a:microsoft:playwright:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 4th percentile among its peer group of 1,749 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (42)

microsoftpatch availablevia msrc
Product: microsoft/playwrightFixed in: 1.55.1
View patch
npmpatch availablevia ghsa
Product: playwrightFixed in: 1.55.1
microsoftvendor investigatingvia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: OpenShift ServerlessFixed in: openshift-serverless-1/kn-backstage-plugins-eventmesh-rhel8
redhatvendor investigatingvia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/acm-grafana-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: org.keycloak-keycloak-parent
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: org.keycloak-keycloak-parent
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/openvsx-rhel9
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: com.github.streamshub-console
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 3Fixed in: com.github.streamshub-console
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py311-rhel9
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: mtv-candidate/mtv-console-plugin-rhel9
redhatvendor investigatingvia redhat_api
Product: Multicluster Global HubFixed in: multicluster-globalhub/multicluster-globalhub-grafana-rhel9

Vendor Advisories (3)

npmGHSA-7mvr-c777-76hphigh

Playwright downloads and installs browsers without verifying the authenticity of the SSL certificate

Oct 14, 2025
redhatCVE-2025-59288Moderate

playwright: Playwright Spoofing Vulnerability

Oct 14, 2025
microsoft2025-Oct/CVE-2025-59288Moderate

Playwright Spoofing Vulnerability

Oct 14, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-59288
Vendor Advisory