Improper Input Validation in Spatie Browsershot Affects Sensitive File Access
CVE-2025-1026

7.7HIGH

Key Information:

Vendor
Spatie
Status
Spatie/browsershot
Vendor
CVE Published:
5 February 2025

Summary

Versions of the Spatie Browsershot package prior to 5.0.5 are impacted by a significant weakness due to inadequate URL validation in the setUrl method. This flaw makes it possible for an attacker to exploit Local File Inclusion (LFI) vulnerabilities, potentially enabling them to access sensitive files stored on the server. Furthermore, this issue serves as a bypass for a previous fix implemented for another related vulnerability, highlighting the importance of robust input validation mechanisms to ensure the security of applications.

Affected Version(s)

spatie/browsershot 0 < 5.0.5

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chua Jian Shen
Ee Yang Tee
.