mediumCVSS 4.2Vulnerability

GHSA-crmm-hgp2-wgrp

A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement. Under certain conditions, a generated temporary signed URL can be interpreted differently by the server than intended at signing time. This may cause requests to resolve to an unintended resource, and can prevent expiration from being enforced, allowing expired URLs to remain valid indefinitely. ### Impact - Expired temporary URLs may continue to be accepted - Requests may resolve to a different resource than the one that was signed - The upload variant may allow writes to reach an unintended destination

Properties

ghsa_id
GHSA-crmm-hgp2-wgrp
severity
medium
summary
Laravel Framework: Temporary Signed URL Path Confusion
cvss_score
4.2
cve_id
GHSA-crmm-hgp2-wgrp
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-06-17T13:54:13Z
source_url
https://github.com/advisories/GHSA-crmm-hgp2-wgrp
ghsa_updated
2026-06-17T13:54:13Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Improper Encoding or Escaping of Output

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]composer/laravel/framework

AFFECTS (1)

[Software]composer/laravel/framework

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-crmm-hgp2-wgrp (CVSS 4.2) — Ninja Signal Threat Intelligence | Ninja Signal