Browsershot version 3.57.3 vulnerable to improper input validation
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Nov 25, 2022 
          to the GitHub Advisory Database
          •
          Updated Apr 29, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Nov 25, 2022 
    
  
        Published to the GitHub Advisory Database
      Nov 25, 2022 
    
  
        Reviewed
      Dec 2, 2022 
    
  
        Last updated
      Apr 29, 2025 
    
  
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
References