Home

Description

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

PUBLISHED Reserved 2025-04-03 | Published 2025-04-04 | Updated 2025-06-08 | Assigner snyk




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N/E:P

Problem types

Server-side Request Forgery (SSRF)

Credits

Ngan Jun Ming

References

gist.github.com/JunMing27/651998a34d57fbf71ff9d25386f1da0f exploit

security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8548015

gist.github.com/JunMing27/651998a34d57fbf71ff9d25386f1da0f

cve.org (CVE-2025-3192)

nvd.nist.gov (CVE-2025-3192)

Download JSON