Описание
DevDojo Voyager Argument Injection vulnerability
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-32931
- https://github.com/lishihihi/voyager-issue-report
- https://github.com/thedevdojo/voyager/blob/1.8/docs/core-concepts/compass.md
- https://github.com/thedevdojo/voyager/blob/7e7e0f4f0e115d2d9e0481a86153a1ceff194c00/resources/views/compass/includes/commands.blade.php#L11-L16
Пакеты
Наименование
tcg/voyager
composer
Затронутые версииВерсия исправления
>= 1.4.0, <= 1.8.0
Отсутствует
Связанные уязвимости
CVSS3: 9.1
nvd
10 месяцев назад
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.