Improper Input Validation in Spatie Browsershot Affects Sensitive File Access
CVE-2025-1026
7.7HIGH
Key Information:
- Vendor
- Spatie
- Status
- Spatie/browsershot
- Vendor
- CVE Published:
- 5 February 2025
Summary
Versions of the Spatie Browsershot package prior to 5.0.5 are impacted by a significant weakness due to inadequate URL validation in the setUrl method. This flaw makes it possible for an attacker to exploit Local File Inclusion (LFI) vulnerabilities, potentially enabling them to access sensitive files stored on the server. Furthermore, this issue serves as a bypass for a previous fix implemented for another related vulnerability, highlighting the importance of robust input validation mechanisms to ensure the security of applications.
Affected Version(s)
spatie/browsershot 0 < 5.0.5
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Chua Jian Shen
Ee Yang Tee