{"id":"CVE-2024-21549","title":"Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method","summary":"Versions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which a…","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-20"],"published":"2024-12-20","updated":"2026-08-06","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-21549","references":[{"url":"https://github.com/spatie/browsershot/commit/f791ce0ae8dd99367dbfa30588ee31e1196e1728","label":"report@snyk.io"},{"url":"https://github.com/spatie/browsershot/discussions/906","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8533023","label":"report@snyk.io"}],"tags":["nvd"],"epss":0.00614,"epssPercentile":0.47093,"ingestedAt":"2026-08-06T17:00:11.400Z","slug":"CVE-2024-21549","body":"## Overview\n\nVersions of the package spatie/browsershot before 5.0.3 are vulnerable to Improper Input Validation due to improper URL validation in the setUrl method. An attacker can exploit this vulnerability by utilizing view-source:file://, which allows for arbitrary file reading on a local file.\r\r**Note:**\r\rThis is a bypass of the fix for [CVE-2024-21544](https://security.snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-8496745).\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}