-
CVSS Score
-A Semantic Attack on Google Gemini - Read the Latest Research
The analysis focused on the changes made in the patch to identify vulnerable functions. The removal of code that evaluates PHP in the load_html function directly points to its vulnerability. The change in dompdf.php related to disallowing php:// streams also indicates a vulnerability in how input files are processed, but the exact function name is not specified in the patch.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dompdf/dompdf | composer | >= 0.6.0, < 0.6.1 | 0.6.1 |