tecnickcom/tcpdf is vulnerable to Path Traversal
60
Medium Risk
Affected versions of this package are vulnerable to path traversal when handling image tags in the openHTMLTagHandler function. An attacker can craft malicious image tags with directory traversal sequences, allowing them to access files outside the intended directory, potentially leading to unauthorized access to sensitive files on the server.
You are affected if you are using a version that falls within the vulnerable range.
tecnickcom/tcpdf is vulnerable to Path Traversal in versions 2.0.000 - 6.7.5.
Upgrade the tecnickcom/tcpdf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant