CVE-2025-27515

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*

History

26 Aug 2025, 17:13

Type Values Removed Values Added
Summary
  • (es) Laravel es un framework de trabajo para aplicaciones web. Al utilizar la validación con comodines para validar un campo de archivo o imagen determinado (`files.*`), una solicitud maliciosa manipulada por el usuario podría eludir las reglas de validación. Esta vulnerabilidad se ha corregido en las versiones 11.44.1 y 12.1.1.
First Time Laravel framework
Laravel
CPE cpe:2.3:a:laravel:framework:*:*:*:*:*:*:*:*
References () https://github.com/laravel/framework/commit/2d133034fefddfb047838f4caca3687a3ba811a5 - () https://github.com/laravel/framework/commit/2d133034fefddfb047838f4caca3687a3ba811a5 - Patch
References () https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4 - () https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-05 19:15

Updated : 2025-08-26 17:13


NVD link : CVE-2025-27515

Mitre link : CVE-2025-27515

CVE.ORG link : CVE-2025-27515


JSON object : View

Products Affected

laravel

  • framework
CWE
CWE-155

Improper Neutralization of Wildcards or Matching Symbols