CVE-2025-1022

CVSS 3.1 Score 8.2 of 10 (high)

Details

Published Feb 5, 2025
CWE ID 20

Summary

CVE-2025-1022 exposes a vulnerability in versions of the spatie/browsershot package below 5.0.5. The issue lies in the setHtml function used by Browsershot::html(). An attacker can bypass the expected input validation by omitting slashes in the file URI, potentially accessing restricted files, such as /etc/passwd, due to the missing validation of file URI schemes. This vulnerability poses a significant risk for unauthorized data access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share