CVE-2019-17050

HIGH EXPLOITED

Voyager < 1.2.7 - Authenticated Arbitrary File Read and Delete via Compass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-17050 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin privileges and Compass access can read or delete arbitrary files, such as the .env file. NOTE: a software maintainer has suggested a solution in which Compass is switched off in a production environment.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://github.com/the-control-group/voyager/issues/4322

Scores

CVSS v3 7.2
EPSS 0.0125
EPSS Percentile 65.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2025-04-29
CWE
CWE-639
Status published
Products (1)
thecontrolgroup/voyager < 1.2.7
Published Sep 30, 2019
Tracked Since Feb 18, 2026