podman-browser
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
AnomalyAnomalybrowse.js
LOWAnomalyLOW
browse.js
No strong evidence of intentional malware (tracking/backdoor/credential theft/exfiltration) in this module. However, it is a security-sensitive headless browsing tool: it fetches attacker-controlled URLs (often leading to SSRF/internal exposure concerns in deployments), runs Chromium with sandbox disabled and shares host IPC (increasing impact if the browser is exploited), and performs runtime npm installation of Playwright without lockfile/checksum verification (supply-chain/integrity risk).
Confidence: 76%Severity: 56%
Audit Metadata