CVE-2025-65346: Alexusmai Laravel File Manager
Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.
alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.
Affected products
- Alexusmai Laravel File Manager: up to and including 3.3.1
Published 2025-12-04. Last modified 2026-06-17.