GHSA-crmm-hgp2-wgrpMedium· 4.2▾ SunlitLaravel Framework: Temporary Signed URL Path Confusion
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement.
Under certain conditions, a generated temporary signed URL can be interpreted differently by the server than intended at signing time. This may cause requests to resolve to an unintended resource, and can prevent expiration from being enforced, allowing expired URLs to remain valid indefinitely.
laravel/framework >= 13.0.0, < 13.12.0laravel/framework < 12.61.1Upgrade to a patched release:
laravel/framework 13.12.0laravel/framework 12.61.1Connected by shared product, vendor, weakness, or advisory.
GHSA-5vg9-5847-vvmqHigh· 8.9Laravel Framework: CRLF injection in default email rule
CVE-2023-29541High· 8.8Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands
CVE-2022-24682Medium· 6.1An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15 patch 30 (update 1), as exploited in the wild starting in December 2021
CVE-2026-25940High· 8.1jsPDF is a library to generate PDFs in JavaScript
CVE-2026-48019High· 8.9Laravel is a web application framework
CVE-2026-55891Low· 0.0PrivateBin is an online pastebin where the server has zero knowledge of pasted data