logo

Laravel admin package Voyager vulnerable to one-click RCE flaw

ID: 976efde6-6e82-5c28-972d-4ab334d3626e

STIX ID: report--976efde6-6e82-5c28-972d-4ab334d3626e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-01-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Three vulnerabilities in the popular Voyager Laravel admin package—an upload MIME-type bypass allowing polyglot file uploads (CVE-2024-55417), a popup JavaScript injection in /admin/compass enabling one-click attacks from an authenticated admin (CVE-2024-55416), and a file management path-manipulation flaw allowing arbitrary file access/deletion (CVE-2024-55415)—were disclosed by SonarSource; maintainers did not respond within the 90-day disclosure period and the issues remain unpatched, so users should restrict access, tighten file-upload/execute controls, and avoid using Voyager in sensitive production environments until fixed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.