GHSA-v528-6rq9-h6gw
GitHub Security Advisory
Spatie Browsershot Directory Traversal vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.
Affected Packages
Packagist
spatie/browsershot
Affected versions:
0
(fixed in 5.0.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 19, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.