Chromedriver is a focused test-automation tool that controls Chromium browsers programmatically, and its vulnerability footprint centers on weaknesses in command handling and data protection within that narrowly scoped product. The observed weakness classes—OS command injection and missing encryption of sensitive data—reflect the risks inherent to a tool that bridges user input and browser process control. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chromedriver Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-26156HIGH Versions of the package chromedriver before 119.0.1 are vulnerable to Command Injection when setting the chromedriver.path to an arbitrary system binary. This could lead to unautho | Nov 9, 2023 | 7.5 | 22 | NO | NO |
CVE-2016-10579HIGH Chromedriver is an NPM wrapper for selenium ChromeDriver. Chromedriver before 2.26.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be pos | Jun 1, 2018 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chromedriver Project.
Media articles that mention a CVE ID that affects a product developed by Chromedriver Project — matched by CVE ID, not by vendor name.