CVE-2025-27515

unknown
Published 2025-03-05 · Modified 2025-03-12
CVSS v3
CVSS v2
VIR risk

Description

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-27515

OS impact

OSVersionStatusFixed in
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed10.48.29+dfsg-1
debian debiansidfixed10.48.29+dfsg-1
debian debiantrixiefixed10.48.29+dfsg-1

Package impact

EcosystemPackageVulnerableFixed
php Packagistlaravel/framework>=12.0.0,<12.1.112.1.1
php Packagistlaravel/framework>=11.0.0,<11.44.111.44.1
php Packagistlaravel/framework<10.48.2910.48.29

References

Verify integrity in audit chain (admin only). AS-IS.