Server-side Request Forgery in Spatie Browsershot by Spatie
CVE-2025-3192
8.8HIGH
What is CVE-2025-3192?
The Spatie Browsershot package is susceptible to Server-side Request Forgery (SSRF) in its setUrl() function. Due to inadequate input validation, an attacker can manipulate the user input to access local resources, including sensitive information from localhost. This vulnerability poses significant risks as it could allow attackers to traverse directories and exploit confidential server details.
Affected Version(s)
spatie/browsershot 0.0.0