VDB
Sign up
MEDIUM6.1

GHSA-6q49-35h6-rq2p

Browsershot version 3.57.3 vulnerable to improper input validation

Quick fix

GHSA-6q49-35h6-rq2p — spatie/browsershot: upgrade to the fixed version with the command below.

composer require spatie/browsershot:^3.57.4

Details

Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spatie/browsershot
Introduced in: 0Fixed in: 3.57.4
Fixcomposer require spatie/browsershot:^3.57.4

References