CVE-2025-65346
CRITICALAlexusmai Laravel File Manager < 3.3.1 - Path Traversal
Title source: ruleDescription
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.
Exploits (1)
Scores
CVSS v3
9.1
EPSS
0.0028
EPSS Percentile
51.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Details
CWE
CWE-22
Status
published
Products (2)
alexusmai/laravel-file-manager
0Packagist
alexusmai/laravel_file_manager
< 3.3.1
Published
Dec 04, 2025
Tracked Since
Feb 18, 2026