Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8c2c-jxwj-jqgf: Browsershot does not validate URL protocols passed to Browsershot URL method

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.

ghsa
#git

Browsershot does not validate URL protocols passed to Browsershot URL method

High severity GitHub Reviewed Published Nov 25, 2022 • Updated Dec 2, 2022

Related news

CVE-2022-41706: GitHub - spatie/browsershot: Convert HTML to an image, PDF or string

Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.