alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality improperly allows archive contents to be written to arbitrary locations on the filesystem due to insufficient validation of extraction paths.
{
"github_reviewed": true,
"github_reviewed_at": "2025-12-05T18:58:07Z",
"nvd_published_at": "2025-12-04T15:15:59Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-22"
]
}