Back to all advisories

Tag: web

3 advisories tagged with "web".

CVE-2026-46683 High

SSRF and local file read via the xsl-style-sheet option

This is a Server-Side Request Forgery (SSRF) and local file read vulnerability in KnpLabs Snappy, a PHP library that wraps wkhtmltopdf for HTML-to-PDF generation. The flaw lives in the xsl-style-sheet option, which is passed directly to wkhtmltopdf without any URL scheme validation. If an attacker can influence the value of that option, they can point it at internal network resources or at local files using file:// URIs, causing the server to fetch and embed content it should never expose.

Snappy
CVE-2026-46643 Medium

Binary path is never shell-escaped due to an inverted is_executable check

CVE-2026-46643 is a Moderate severity vulnerability in knplabs/knp-snappy (<= 1.7.0) where the binary path passed to Snappy's constructor is never shell-escaped before being executed, despite code that looks like it should be doing exactly that. The root cause is a logic inversion in the is_executable() check. escapeshellarg() wraps the path in single quotes, but is_executable() then looks for a file whose name literally contains those quote characters, which never exists.

Snappy
GHSA-87qc-37cw-84h4 Low

$temporaryFiles is public, enabling arbitrary file deletion at shutdown

GHSA-87qc-37cw-84h4 is a Low severity vulnerability in knplabs/knp-snappy (<= 1.7.1) where the $temporaryFiles property on AbstractGenerator is declared public instead of private. Snappy uses this array to track temp files it creates during generation, then deletes everything in it automatically when the object is destroyed at shutdown via __destruct().

Snappy

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →