{"id":"CVE-2024-21547","aliases":["GHSA-v528-6rq9-h6gw"],"url":"https://o3.security/vulnerability/CVE-2024-21547","summary":"Spatie Browsershot Directory Traversal vulnerability","details":"Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\\\. An attacker could read any file on the server by exploiting the normalization of \\ into /.","published":"2024-12-18T06:06:04.591Z","modified":"2026-08-12T03:51:11.367647480Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"spatie/browsershot","fixedVersion":"5.0.2"}],"fix":{"url":"https://github.com/spatie/browsershot/commit/dfc3635b83dd980e5c39f8f8c73e87723b99ca01","label":"spatie/browsershot@dfc3635"},"references":[{"type":"WEB","url":"https://gist.github.com/chuajianshen/baa71db588cfc038fb5d65624a47be81"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8501858"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21547.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21547"},{"type":"FIX","url":"https://github.com/spatie/browsershot/commit/dfc3635b83dd980e5c39f8f8c73e87723b99ca01"},{"type":"PACKAGE","url":"https://github.com/spatie/browsershot"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.367647480Z"}}