{"id":"CVE-2024-21549","aliases":["GHSA-c9f5-29f6-c35w"],"url":"https://o3.security/vulnerability/CVE-2024-21549","summary":"Browsershot Improper Input Validation vulnerability","details":"Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.\r\r**Note:**\r\rThis is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).","published":"2024-12-20T05:00:01.462Z","modified":"2026-08-08T03:48:01.506191289Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"spatie/browsershot","fixedVersion":"5.0.3"}],"fix":{"url":"https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728","label":"spatie/browsershot@f791ce0"},"references":[{"type":"WEB","url":"https://github.com/spatie/browsershot/discussions/906"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21549.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21549"},{"type":"FIX","url":"https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:01.506191289Z"}}