CVE-2026-48067Medium· 6.5▾ SunlitFilament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.3%
The recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value.
filament/tables >= 3.0.0, <= 3.3.50filament/actions >= 4.0.0, <= 4.11.3filament/actions >= 5.0.0, <= 5.6.3Upgrade to a patched release:
filament/tables 3.3.51filament/actions 4.11.4filament/actions 5.6.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77567High· 8.1Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84307Low· 3.7Filament is a collection of full-stack components for accelerated Laravel development
CVE-2026-84306Medium· 6.5Filament is a collection of full-stack components for accelerated Laravel development
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)
CVE-2026-55409High· 7.6Filament: Disabled RichEditor field state can be used for XSS