HIGH8.2
GHSA-8c2c-jxwj-jqgf
Browsershot does not validate URL protocols passed to Browsershot URL method
Quick fix
GHSA-8c2c-jxwj-jqgf — spatie/browsershot: upgrade to the fixed version with the command below.
composer require spatie/browsershot:^3.57.3Details
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/spatie/browsershot
Introduced in:
0Fixed in: 3.57.3Fix
composer require spatie/browsershot:^3.57.3