Laravel Valet Official Documentationproduct
https://laravel.com/docs/8.x/valet CVE-2021-47756
HIGH
Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)
Record summary
CVE-2021-47756 has a selected CVSS score of 8.4 (high); EIP currently links 1 catalogued exploit.
Description
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Laravel ValetBrowse Laravel / Laravel Valet | CVE List | 1.1.4 to 2.0.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBLaravel Valet 2.0.3 - Local Privilege Escalation (macOS)ExploitDB exploitby leonjzaNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47756 ExploitDB-50591exploit
https://www.exploit-db.com/exploits/50591 VulnCheck Advisory: Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)Third-party advisory
https://www.vulncheck.com/advisories/laravel-valet-local-privilege-escalation-macos