Low severity3.7NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026
CVE-2026-105125
CVE-2026-105125
Description
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Affected products
1- Range: <1.4.8
Patches
Vulnerability mechanics
References
6- github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.phpnvd
- github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505envd
- github.com/laradashboard/laradashboard/pull/350nvd
- github.com/laradashboard/laradashboard/releases/tag/v1.4.8nvd
- github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cghnvd
- www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpointnvd
News mentions
0No linked articles in our index yet.