Home

Description

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.

PUBLISHED Reserved 2025-11-18 | Published 2025-12-03 | Updated 2025-12-05 | Assigner mitre

References

github.com/alexusmai/laravel-file-manager

github.com/tlekrean/CVE-2025-65345

cve.org (CVE-2025-65345)

nvd.nist.gov (CVE-2025-65345)