CVE-2026-105125

Summary

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.

Affected Software

VendorProductVersion RangeStatus
laradashboardlaradashboard0 < 1.4.8affected
laradashboardlaradashboard1.4.8unaffected

Weaknesses

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

References