chrome-cdp
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecurityscripts/inject.mjs
MEDIUMSecurityMEDIUM
scripts/inject.mjs
This module is an automation-style CDP injector that will load and execute a remote JavaScript URL in a target browser tab via Runtime.evaluate + DOM <script> injection. While it contains no explicit exfiltration or persistence logic in the shown fragment, its design is inherently high-impact because any untrusted or attacker-controlled --url results in arbitrary page-context script execution. The absence of URL validation/allowlisting and reliance on a user-supplied CDP endpoint materially increase misuse risk.
Confidence: 68%Severity: 72%
Audit Metadata