VDB
Sign up
HIGH8.6

GHSA-g2r4-phv7-5fgv

Browsershot Local File Inclusion

Quick fix

GHSA-g2r4-phv7-5fgv — spatie/browsershot: upgrade to the fixed version with the command below.

composer require spatie/browsershot:^5.0.1

Details

Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spatie/browsershot
Introduced in: 0Fixed in: 5.0.1
Fixcomposer require spatie/browsershot:^5.0.1

References