PhantomJS is a headless browser engine historically used for web automation, testing, and screenshot capture, with a narrow product footprint centered on the core application itself. Its reported vulnerability profile clusters around file-system access control, reflecting the product's need to interact with local resources during scriptable browser operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phantomjs over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17221HIGH PhantomJS through 2.1.1 has an arbitrary file read vulnerability, as demonstrated by an XMLHttpRequest for a file:// URI. The vulnerability exists in the page.open() function of th | Nov 5, 2019 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phantomjs.
Media articles that mention a CVE ID that affects a product developed by Phantomjs — matched by CVE ID, not by vendor name.