cve/2025/CVE-2025-1026.md
2025-09-29 21:09:30 +02:00

1.0 KiB

CVE-2025-1026

Description

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files.

Note:

This is a bypass of the fix for CVE-2024-21549.

POC

Reference

Github

No PoCs found on GitHub currently.