<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[JSReport Puppeteer vulnerabilities]]></title><description><![CDATA[<p>Hello JSReport Support Team,</p>
<p>During our latest AWS Inspector security scan on the JSReport production deployment, multiple critical and high-level vulnerabilities were detected originating from the Puppeteer dependency bundled with JSReport.</p>
<p>We request guidance on the following:<br />
• Whether there is a patched/updated JSReport release that resolves the Puppeteer-related vulnerabilities.<br />
• If there is a recommended workaround or manual upgrade process for Puppeteer versions inside JSReport.<br />
• Any official security best practices to mitigate this issue while continuing to run JSReport in production?</p>
<p>This vulnerability is impacting our production security compliance, so we request your assistance as soon as possible.</p>
<p>Thanks and Regards,</p>
<hr />
<p>Gaurav Kelkar</p>
]]></description><link>https://forum.jsreport.net/topic/3509/jsreport-puppeteer-vulnerabilities</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 00:45:57 GMT</lastBuildDate><atom:link href="https://forum.jsreport.net/topic/3509.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 26 Nov 2025 05:23:40 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to JSReport Puppeteer vulnerabilities on Invalid Date]]></title><description><![CDATA[<p>Hello JSReport Support Team,</p>
<p>During our latest AWS Inspector security scan on the JSReport production deployment, multiple critical and high-level vulnerabilities were detected originating from the Puppeteer dependency bundled with JSReport.</p>
<p>We request guidance on the following:<br />
• Whether there is a patched/updated JSReport release that resolves the Puppeteer-related vulnerabilities.<br />
• If there is a recommended workaround or manual upgrade process for Puppeteer versions inside JSReport.<br />
• Any official security best practices to mitigate this issue while continuing to run JSReport in production?</p>
<p>This vulnerability is impacting our production security compliance, so we request your assistance as soon as possible.</p>
<p>Thanks and Regards,</p>
<hr />
<p>Gaurav Kelkar</p>
]]></description><link>https://forum.jsreport.net/post/14813</link><guid isPermaLink="true">https://forum.jsreport.net/post/14813</guid><dc:creator><![CDATA[sysadmin-ispl]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Reply to JSReport Puppeteer vulnerabilities on Invalid Date]]></title><description><![CDATA[<p>The dependencies will be updated with the next release as always.<br />
<a href="https://github.com/jsreport/jsreport?tab=readme-ov-file#vulnerabilities" rel="nofollow">https://github.com/jsreport/jsreport?tab=readme-ov-file#vulnerabilities</a></p>
<p>The release is scheduled for this week.</p>
]]></description><link>https://forum.jsreport.net/post/14814</link><guid isPermaLink="true">https://forum.jsreport.net/post/14814</guid><dc:creator><![CDATA[admin]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Reply to JSReport Puppeteer vulnerabilities on Invalid Date]]></title><description><![CDATA[<p>Hello,</p>
<p>There are still some puppeteer related vulnerbilities are present.<br />
All are in high in state so it is possible to provide one more update for this?</p>
<p>Regards<br />
<img src="/uploads/files/1765443393862-upload-8cfffd70-40e9-4974-a53c-7e943864f01c-resized.png" alt="0_1765443391554_upload-8cfffd70-40e9-4974-a53c-7e943864f01c" class="img-responsive img-markdown" /></p>
]]></description><link>https://forum.jsreport.net/post/14827</link><guid isPermaLink="true">https://forum.jsreport.net/post/14827</guid><dc:creator><![CDATA[sysadmin-ispl]]></dc:creator><pubDate>Invalid Date</pubDate></item><item><title><![CDATA[Reply to JSReport Puppeteer vulnerabilities on Fri, 12 Dec 2025 14:19:01 GMT]]></title><description><![CDATA[<p>We will again update puppeteer/chromium in the next release. As always. Likely soon.</p>
<p>If you need to update just now, go ahead and update the puppeteer dependency.<br />
You just need to list the latest puppeteer dependency in your package.json.</p>
<p>Or build your own Docker image with the updated Chromium. However, note that the latest Chromium with the fix is not yet in the public repository at the time of writing this post.</p>
]]></description><link>https://forum.jsreport.net/post/14828</link><guid isPermaLink="true">https://forum.jsreport.net/post/14828</guid><dc:creator><![CDATA[admin]]></dc:creator><pubDate>Fri, 12 Dec 2025 14:19:01 GMT</pubDate></item><item><title><![CDATA[Reply to JSReport Puppeteer vulnerabilities on Invalid Date]]></title><description><![CDATA[<p>I have the same issue</p>
]]></description><link>https://forum.jsreport.net/post/14872</link><guid isPermaLink="true">https://forum.jsreport.net/post/14872</guid><dc:creator><![CDATA[Owenpauly]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>