LOW
GHSA-hwmc-r6mf-jh83
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
Quick fix
GHSA-hwmc-r6mf-jh83 — spatie/schema-org: upgrade to the fixed version with the command below.
composer require spatie/schema-org:^3.23.2Details
Schema.org has a cross-site scripting (XSS) vulnerability via script break-out in toScript() output.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/spatie/schema-org
Introduced in:
3.23.1Fixed in: 3.23.2Fix
composer require spatie/schema-org:^3.23.2Packagist/spatie/schema-org
Introduced in:
4.0.0Fixed in: 4.0.2Fix
composer require spatie/schema-org:^4.0.2References
- https://github.com/spatie/schema-org/pull/242[WEB]
- https://github.com/spatie/schema-org/commit/be389b4759214c11cc1364a16e34a929c5af5a88[WEB]
- https://github.com/FriendsOfPHP/security-advisories/blob/master/spatie/schema-org/2026-04-20.yaml[WEB]
- https://github.com/spatie/schema-org[PACKAGE]
- https://github.com/spatie/schema-org/releases/tag/4.0.2[WEB]