CVE-2026-105125
6.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| laradashboard | laradashboard | 0 < 1.4.8 | affected |
| laradashboard | laradashboard | 1.4.8 | unaffected |
Weaknesses
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
References
- https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46
- https://github.com/laradashboard/laradashboard/pull/350
- https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e
- https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
- https://github.com/laradashboard/laradashboard
- https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.