CVE-2025-65346: Alexusmai Laravel File Manager

Critical severity, CVSS 9.1. EPSS: 1% chance of exploitation in the next 30 days.

alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.

Affected products

  • Alexusmai Laravel File Manager: up to and including 3.3.1

Published 2025-12-04. Last modified 2026-06-17.