CVE-2025-32931 Information
Apr 15, 2025
cve
Description
DevDojo Voyager 1.4.0 through 1.8.0 when Laravel 8 or later is used allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Reference
https://github.com/lishihihi/voyager-issue-report/ https://github.com/thedevdojo/voyager/blob/1.8/docs/core-concepts/compass.md https://github.com/thedevdojo/voyager/blob/7e7e0f4f0e115d2d9e0481a86153a1ceff194c00/resources/views/compass/includes/commands.blade.php#L11-L16
Share on: