Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9704 | Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories. |
Github GHSA |
GHSA-qw64-6vcc-8ghx | Browsershot Server-Side Request Forgery (SSRF) via setURL() Function |
Fri, 04 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Apr 2025 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package spatie/browsershot from 0.0.0 are vulnerable to Server-side Request Forgery (SSRF) in the setUrl() function due to a missing restriction on user input, enabling attackers to access localhost and list all of its directories. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-06-08T22:07:30.269Z
Reserved: 2025-04-03T09:46:47.272Z
Link: CVE-2025-3192
Updated: 2025-04-04T14:07:11.178Z
Status : Deferred
Published: 2025-04-04T05:15:45.743
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-3192
No data.
OpenCVE Enrichment
Updated: 2025-06-24T09:44:21Z
EUVD
Github GHSA