A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled, allowing an attacker to craft a favicon reference to a loopback address, private IP address, or another resource reachable only from the PlaywrightCapture host. This could enable internal service discovery and unauthorized access. Organizations using PlaywrightCapture [truncated]
CVE-2026-63175 is a vulnerability in PlaywrightCapture where capture-specific configuration and runtime data were stored as mutable class-level variables instead of instance-level variables. This allowed multiple Capture objects within the same Python process to share state, including sensitive information like HTTP headers, cookies, and authentication credentials. Consequently, in a multi-user or concurr [truncated]