CVE-2025-3192
CVSS 3.1 Score 8.2 of 10 (high)
Details
Summary
CVE-2025-3192 is a serious vulnerability affecting the spatie/browsershot package, versions 0.0.0 and above. This issue enables Server-side Request Forgery (SSRF), allowing attackers to manipulate the setUrl() function and access localhost. By doing so, attackers can list all of the directories on the affected server, potentially leading to the exposure of sensitive data. This vulnerability poses a significant risk, as it can be exploited remotely without the need for user interaction. It is strongly recommended that users update their packages to the latest version as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.