CVE-2025-65346

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/12/2025
Last modified:
16/12/2025

Description

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alexusmai:laravel_file_manager:*:*:*:*:*:*:*:* 3.3.1 (including)