VYPR
Critical severity9.1NVD Advisory· Published Apr 14, 2025· Updated Apr 15, 2026

CVE-2025-32931

CVE-2025-32931

Description

DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
tcg/voyagerPackagist
>= 1.4.0, <= 1.8.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.