VDB
Sign up
MEDIUM5.3

GHSA-rv74-mh27-4jpv

browsershot local file inclusion vulnerability

Quick fix

GHSA-rv74-mh27-4jpv — spatie/browsershot: upgrade to the fixed version with the command below.

composer require spatie/browsershot:^3.40.1

Details

This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spatie/browsershot
Introduced in: 0Fixed in: 3.40.1
Fixcomposer require spatie/browsershot:^3.40.1

References