Vulnerability Description
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alexusmai | Laravel File Manager | <= 3.3.1 |
Related Weaknesses (CWE)
References
- https://github.com/Theethat-Thamwasin/CVE-2025-65346Third Party Advisory
- https://github.com/alexusmai/laravel-file-managerProduct
- https://github.com/Theethat-Thamwasin/CVE-2025-65346/blob/main/POC-CVE-65346.mdExploitThird Party Advisory
FAQ
What is CVE-2025-65346?
CVE-2025-65346 is a vulnerability with a CVSS score of 9.1 (CRITICAL). alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the f...
How severe is CVE-2025-65346?
CVE-2025-65346 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-65346?
Check the references section above for vendor advisories and patch information. Affected products include: Alexusmai Laravel File Manager.