GHSA-px5g-fvm6-m9frMediumCVSS 3.7
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated...
🔗 CVE IDs covered (1)
📋 Description
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
🔗 References (9)
- https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh
- https://nvd.nist.gov/vuln/detail/CVE-2026-105125
- https://github.com/laradashboard/laradashboard/pull/350
- https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e
- https://github.com/laradashboard/laradashboard
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46
- https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
- https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint
- https://github.com/advisories/GHSA-px5g-fvm6-m9fr