CVE-2026-105125
LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
| CWE | CWE-22 |
| Vendor | laradashboard |
| Product | laradashboard |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for laradashboard laradashboard
Be the first to know when new low vulnerabilities affecting laradashboard laradashboard are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
laradashboard / laradashboard
0 < 1.4.8
References
github.com: https://github.com/laradashboard/laradashboard/security/advisories/GHSA-43jp-66c9-7cgh github.com: https://github.com/laradashboard/laradashboard/blob/v1.4.2/routes/api.php#L36-L46 github.com: https://github.com/laradashboard/laradashboard/pull/350 github.com: https://github.com/laradashboard/laradashboard/commit/aa5d33a32ccef07618ae8687247540d73a21505e github.com: https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8 github.com: https://github.com/laradashboard/laradashboard vulncheck.com: https://www.vulncheck.com/advisories/laradashboard-before-1.4.8-path-traversal-via-api-translations-lang-endpoint
Credits
EVIL0RD