CVE-2025-3192: SSRF

Published Apr 4, 2025
·
Updated

Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

Other sources

Versions of the package spatie/browsershot from 0.0.0 to 5.0.3 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories.

GitHub

Affected Software

2 affected components
spatie browsershot>=0.0.0
composer/spatie/browsershot<=5.0.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade spatie/browsershot to a version that resolves this vulnerability.

    Fixed in 5.0.3
  2. Compensating control

    Ensure user input passed to spatie/browsershot setUrl() is restricted/validated so it cannot be used to access localhost or perform directory listing (SSRF mitigation).

Event History

Apr 4, 2025
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:34 AM
Jul 11, 57244
Event
via FIRST·09:19 PM

Frequently Asked Questions

1

What is the severity of CVE-2025-3192?

CVE-2025-3192 has a medium severity due to its potential for Server-side Request Forgery (SSRF) vulnerabilities.

2

How do I fix CVE-2025-3192?

To fix CVE-2025-3192, update the Spatie Browsershot package to a version that mitigates this vulnerability.

3

What versions are affected by CVE-2025-3192?

CVE-2025-3192 affects all versions of the Spatie Browsershot package starting from 0.0.0.

4

What type of attack does CVE-2025-3192 allow?

CVE-2025-3192 allows for Server-side Request Forgery (SSRF) attacks that enable access to localhost and its directories.

5

Is user input properly validated in CVE-2025-3192?

No, CVE-2025-3192 is due to a lack of restriction on user input in the setUrl() function.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203