rootpwn

medium · CVSS v3 3.7 · CVSS v4 6.3 · EPSS 0.0031

CVE-2026-105125

LaraDashboard versions prior to 1.4.8 allow unauthenticated path traversal via the {lang} route, enabling attackers to read arbitrary JSON f

Overview

LaraDashboard versions prior to 1.4.8 allow unauthenticated path traversal via the {lang} route, enabling attackers to read arbitrary JSON files on Windows hosts. The flaw is triggered by URL-encoded backslash sequences that escape the resources/lang directory. This can expose sensitive configuration files such as composer.json.

Description

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.

Impact

Confidentiality is compromised as attackers can read application JSON files, potentially revealing sensitive data. Integrity and availability are not directly affected. Defenders of Windows-based LaraDashboard installations should be aware that unauthenticated users can access these files.

Remediation

Apply the official patch to upgrade to version 1.4.8 or later. If upgrading is not possible, restrict access to the /resources/lang path via web‑server configuration and validate the {lang} parameter to disallow backslash or dot sequences. Additionally, configure the application to prevent file reads outside the intended directory.

Risk context

The vulnerability has a medium CVSS v3 score of 3.7 and a low EPSS of 0.0031, indicating a modest likelihood of exploitation. While the risk is not high, defenders should still address it promptly to prevent potential data leakage.

Affected products

  • LaraDashboard 1.4.7
  • LaraDashboard 1.4.6
  • LaraDashboard 1.4.5
  • LaraDashboard 1.4.4
  • LaraDashboard 1.4.3
  • LaraDashboard 1.4.2
  • LaraDashboard 1.4.1
  • LaraDashboard 1.4.0

Scores

Severity
medium
CVSS v2
2.6
CVSS v3
3.7
CVSS v4
6.3
EPSS
0.0031

path-traversal unauthenticated Windows LaraDashboard file-read medium-severity

← All CVEs