Headline
GHSA-8c2c-jxwj-jqgf: Browsershot does not validate URL protocols passed to Browsershot URL method
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Browsershot does not validate URL protocols passed to Browsershot URL method
High severity GitHub Reviewed Published Nov 25, 2022 • Updated Dec 2, 2022
Related news
CVE-2022-41706: GitHub - spatie/browsershot: Convert HTML to an image, PDF or string
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.