CVE-2025-48490

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-48490
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48490.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48490
Aliases
Published
2025-05-30T06:15:28Z
Modified
2025-05-31T04:20:40.685113Z
Summary
[none]
Details

Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions), malicious actors could exploit this behavior by crafting requests that bypass expected validation rules, potentially injecting unexpected or dangerous parameters into the application. This could lead to unauthorized data being accepted or processed by the API, depending on the context in which the validation was bypassed. This issue has been patched in version 2.13.0.

References

Affected packages

Git / github.com/lomkit/laravel-rest-api

Affected ranges

Type
GIT
Repo
https://github.com/lomkit/laravel-rest-api
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.1.0-beta
v0.2.0-beta
v0.3.0-beta
v0.4.0-beta
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6

v1.*

v1.0.0
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.0.7
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.4
v1.2.0

v2.*

v2.0.0
v2.1.0
v2.1.1
v2.1.2
v2.10.0
v2.11.0
v2.12.0
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.5.0
v2.5.1
v2.5.2
v2.6.0
v2.7.0
v2.8.0
v2.8.1
v2.8.2
v2.8.3
v2.8.4
v2.8.5
v2.8.6
v2.8.7
v2.9.0