{"id":"CVE-2020-24941","aliases":["BIT-laravel-2020-24941","GHSA-w68r-5p45-5rqp"],"url":"https://o3.security/vulnerability/CVE-2020-24941","summary":"Improper Input Validation in Laravel","details":"An issue was discovered in Laravel before 6.18.35 and 7.x before 7.24.0. The $guarded property is mishandled in some situations involving requests with JSON column nesting expressions.","published":"2020-09-04T02:15:10.787Z","modified":"2026-07-08T16:28:15.685810Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"laravel/framework","fixedVersion":"6.18.35"},{"ecosystem":"Packagist","name":"laravel/framework","fixedVersion":"7.24.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://blog.laravel.com/security-release-laravel-61835-7240"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T16:28:15.685810Z"}}