PT-2025-14839 · Unknown · Spatie/Browsershot

Published

2025-04-04

·

Updated

2025-04-09

·

CVE-2025-3192

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions spatie/browsershot versions 0.0.0 through 3.1
Description The issue is related to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input. This enables attackers to access localhost and list all of its directories. Attackers can exploit this to access localhost files.
Recommendations For versions 0.0.0 through 3.1, update to a secure version as soon as possible to mitigate the risk of Server-side Request Forgery (SSRF). As a temporary workaround, consider restricting the use of the setUrl() function until a patch is available.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2025-3192
GHSA-QW64-6VCC-8GHX

Affected Products

Spatie/Browsershot