HIGH8.6
GHSA-c9f5-29f6-c35w
Browsershot Improper Input Validation vulnerability
Quick fix
GHSA-c9f5-29f6-c35w — spatie/browsershot: upgrade to the fixed version with the command below.
composer require spatie/browsershot:^5.0.3Details
Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.
**Note:**
This is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/spatie/browsershot
Introduced in:
0Fixed in: 5.0.3Fix
composer require spatie/browsershot:^5.0.3References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21549[ADVISORY]
- https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728[WEB]
- https://github.com/spatie/browsershot[PACKAGE]
- https://github.com/spatie/browsershot/discussions/906[WEB]
- https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023[WEB]