Vulnerability Description
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/laradashboard/laradashboard
- https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L4
- https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae868724
- https://github.com/laradashboard/laradashboard/pull/350
- https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8
- https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c
- https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-v
FAQ
What is CVE-2026-105125?
CVE-2026-105125 is a vulnerability with a CVSS score of 3.7 (LOW). LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can se...
How severe is CVE-2026-105125?
CVE-2026-105125 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-105125?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.