CVE-2025-1026: Input Validation
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method, which results in a Local File Inclusion allowing the attacker to read sensitive files.
Note:
This is a bypass of the fix for CVE-2024-21549.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/spatie/browsershotto a version that resolves this vulnerability.Fixed in 5.0.5 - Upgrade
Upgrade
spatie/browsershotto a version that resolves this vulnerability.Fixed in 5.0.5
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1026?
CVE-2025-1026 has a high severity due to the potential for Local File Inclusion resulting in exposure of sensitive files.
How do I fix CVE-2025-1026?
To fix CVE-2025-1026, upgrade the spatie/browsershot package to version 5.0.5 or later.
What vulnerability does CVE-2025-1026 address?
CVE-2025-1026 addresses an issue of improper URL validation in the setUrl method of spatie/browsershot.
What is the impact of CVE-2025-1026?
The impact of CVE-2025-1026 allows attackers to read sensitive files on the server due to Local File Inclusion.
Which versions of spatie/browsershot are affected by CVE-2025-1026?
Versions of spatie/browsershot before 5.0.5 are affected by CVE-2025-1026.