{"id":"CVE-2020-19316","aliases":["GHSA-w2pm-r78h-4m7v"],"url":"https://o3.security/vulnerability/CVE-2020-19316","summary":"OS Command Injection in Laravel Framework","details":"OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.","published":"2021-12-20T20:15:07.593Z","modified":"2026-07-08T19:01:46.971711Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"laravel/framework","fixedVersion":"5.8.17"}],"fix":{"url":"https://github.com/laravel/framework/commit/44c3feb604944599ad1c782a9942981c3991fa31","label":"laravel/framework@44c3feb"},"references":[{"type":"FIX","url":"https://github.com/laravel/framework/commit/44c3feb604944599ad1c782a9942981c3991fa31"},{"type":"EVIDENCE","url":"http://www.netbytesec.com/advisories/OSCommandInjectionInLaravelFramework/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:01:46.971711Z"}}