CVE-2025-65345: Alexusmai Laravel File Manager

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality allows an attacker to create archives containing files and directories outside the intended scope due to improper path validation.

Affected products

  • Alexusmai Laravel File Manager: up to and including 3.3.1

Published 2025-12-03. Last modified 2026-06-17.