Laravel · Laravel · CVE-2025-32931
Name of the Vulnerable Software and Affected Versions:
DevDojo Voyager versions 1.4.0 through 1.8.0
Description:
The issue allows authenticated administrators to execute arbitrary OS commands via a specific `php artisan` command when Laravel 8 or later is used.
Recommendations:
For DevDojo Voyager versions 1.4.0 through 1.8.0, consider restricting access to the specific `php artisan` command that allows arbitrary OS command execution until a patch is available.