Skip to content

File Validation Bypass

Moderate
taylorotwell published GHSA-78fx-h6xr-vch4 Mar 5, 2025

Package

composer laravel/framework (Composer)

Affected versions

<11.44.1,>=12,<12.1.1

Patched versions

12.1.1,11.44.1

Description

When using wildcard validation to validate a given file or image field array (files.*), a user-crafted malicious request could potentially bypass the validation rules.

Severity

Moderate

CVE ID

CVE-2025-27515

Weaknesses

No CWEs

Credits