CVE-2025-1022
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Feb 5, 2025
CWE ID 20
Summary
CVE-2025-1022 exposes a vulnerability in versions of the spatie/browsershot package below 5.0.5. The issue lies in the setHtml function used by Browsershot::html(). An attacker can bypass the expected input validation by omitting slashes in the file URI, potentially accessing restricted files, such as /etc/passwd, due to the missing validation of file URI schemes. This vulnerability poses a significant risk for unauthorized data access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share