CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105125

LOWCVSS 3.7NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or oth

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-105125 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-105125

LOWCVSS 3.7NVD feed

Published 4 October 2026 · tracked since 4 October 2026

Description

LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or oth

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]