CVE-2024-42485: Pxlrbt Filament Excel
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file without login when the webserver allows `../` in the URL. Patched with Version v2.3.3.
Affected products
- Pxlrbt Filament Excel: from 1.0.0, before 1.1.14 (fixed in 1.1.14); from 2.0.0, before 2.3.3 (fixed in 2.3.3)
Published 2024-08-12. Last modified 2026-06-17.