Improper Input Validation in Spatie Browsershot Affects Sensitive File Access
CVE-2025-1026
What is CVE-2025-1026?
Versions of the Spatie Browsershot package prior to 5.0.5 are impacted by a significant weakness due to inadequate URL validation in the setUrl method. This flaw makes it possible for an attacker to exploit Local File Inclusion (LFI) vulnerabilities, potentially enabling them to access sensitive files stored on the server. Furthermore, this issue serves as a bypass for a previous fix implemented for another related vulnerability, highlighting the importance of robust input validation mechanisms to ensure the security of applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
spatie/browsershot 0 < 5.0.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
