CVE-2025-32931
CRITICALDescription
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Is your site exposed to CVE-2025-32931?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2025-32931? +
How severe is CVE-2025-32931? +
How do I check if I'm vulnerable to CVE-2025-32931? +
Related Vulnerabilities
BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the …
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution …
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a …
Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, src/core/git/gitCommand.ts execGitShallowClone passes the --remote-branch value directly …
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations …
A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument. A …