Critical severity9.8NVD Advisory· Published Jun 7, 2020· Updated Jun 17, 2026
CVE-2020-13909
CVE-2020-13909
Description
The Ignition component before 2.0.5 for Laravel mishandles globals, _get, _post, _cookie, and _env. NOTE: in the 1.x series, versions 1.16.15 and later are unaffected as a consequence of the CVE-2021-43996 fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
facade/ignitionPackagist | >= 2.0.0, < 2.0.5 | 2.0.5 |
facade/ignitionPackagist | < 1.16.15 | 1.16.15 |
Affected products
3- Laravel/Ignitiondescription
Patches
Vulnerability mechanics
References
6- github.com/facade/ignition/compare/2.0.4...2.0.5nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-m5v7-pr32-mjx2ghsaADVISORY
- github.com/facade/ignition/releases/tag/2.0.5nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-13909ghsaADVISORY
- github.com/github/advisory-database/issues/2316ghsaWEB
- www.cve.org/CVERecordghsaWEB
News mentions
0No linked articles in our index yet.