VYPR
Low severity3.7NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026

CVE-2026-105125

CVE-2026-105125

Description

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.