VDB
Sign up
MEDIUM6.1

GHSA-82h9-v8vh-mfpq

Browsershot vulnerable to Cross-Site Scripting (XSS)

Quick fix

GHSA-82h9-v8vh-mfpq — spatie/browsershot: upgrade to the fixed version with the command below.

composer require spatie/browsershot:^3.57.3

Details

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spatie/browsershot
Introduced in: 0Fixed in: 3.57.3
Fixcomposer require spatie/browsershot:^3.57.3

References