spatie/image-optimizer is vulnerable to Deserialization of Untrusted Data
50
Medium Risk
Affected versions of the spatie/image-optimizer package deserialize untrusted data without sufficiently verifying that the resulting data is valid. The package fails to apply adequate checks when copying an image file, which could lead to potential security risks.
You are affected if you are using a version that falls within the vulnerable range.
spatie/image-optimizer is vulnerable to Deserialization of Untrusted Data in versions 0.0.3 - 1.7.2.
Upgrade the spatie/image-optimizer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant