Sceawere

Vulnerability Detail

CVE-2026-105125UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

LaraDashboard Path Traversal Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
3h ago
Vendor
laradashboard
Product
laradashboard
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-10-04T00:16:35.990Z",
  "pubdate": "2026-10-04T00:16:35.990Z",
  "executiveSummary": "LaraDashboard versions prior to 1.4.8 are susceptible to an unauthenticated path traversal vulnerability.\nThe vulnerability originates from improper neutralization of directory traversal sequences within the {lang} route segment.\nOn Windows-based hosting environments, attackers can manipulate the input using URL-encoded backslash sequences to escape the intended directory scope.\nThis flaw allows unauthorized read access to sensitive JSON files located within the application structure, such as composer.json.\nThe risk is categorized as high, as it facilitates information disclosure of application configuration and dependencies without requiring authentication.\nSuccessful exploitation exposes critical system metadata, which can be leveraged by an attacker to facilitate further reconnaissance or subsequent attacks against the application's infrastructure.",
  "technicalDetails": "The vulnerability resides in the handling of the {lang} route segment within the LaraDashboard application. The affected component fails to strictly validate or sanitize user-supplied input before using it to construct file system paths.\nThe root cause is an incomplete filter mechanism that permits directory traversal sequences when processed by the underlying operating system's file I/O operations. Specifically, on Windows platforms, the application fails to normalize backslash sequences correctly.\nAn unauthenticated attacker can craft a malicious HTTP request by injecting URL-encoded characters, such as ..%5C, into the {lang} parameter. When the application receives this input, the directory traversal sequence is interpreted by the Windows file system as a instruction to move up the directory hierarchy.\nBy escaping the resources/lang directory, an attacker can traverse to the application root or other sensitive directories. For instance, a payload like /..%5C..%5Ccomposer.json forces the application to resolve the path relative to the intended directory, ultimately retrieving the contents of the target JSON file.\nSince the vulnerability is exploitable via the URL path, no authentication or administrative privileges are required to initiate the attack. The attack surface is exposed over the network, allowing remote actors to read arbitrary JSON files that the web server process has read access to.\nThe technical impact includes the potential exposure of sensitive environment variables, package dependencies, and internal application metadata stored in JSON format. This sensitive information provides an attacker with deep insight into the application's technology stack and configuration, which can be used to identify further vulnerabilities or sensitive endpoints for targeted exploitation.\nThe vulnerability affects all versions of LaraDashboard prior to 1.4.8, indicating a lack of robust input validation logic during the construction of file paths across these versions."
}
CVE-2026-105125: LaraDashboard Path Traversal Vulnerability (LOW Severity, CVSS: 3.7) | Sceawere