VDB
Sign up
HIGH7.5

GHSA-v528-6rq9-h6gw

Spatie Browsershot Directory Traversal vulnerability

Quick fix

GHSA-v528-6rq9-h6gw — spatie/browsershot: upgrade to the fixed version with the command below.

composer require spatie/browsershot:^5.0.2

Details

Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spatie/browsershot
Introduced in: 0Fixed in: 5.0.2
Fixcomposer require spatie/browsershot:^5.0.2

References