{"id":"GHSA-3wgq-h4fr-cwg5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3wgq-h4fr-cwg5","summary":"laravel-crud-wizard-free has File Validation Bypass ","details":"### Impact\nMedium\n\n### Patches\nVersion 3.4.17 fixes illuminate/validation v 8.0.0 to 11.44.0\n\n### Workarounds\nRegister \\MacropaySolutions\\LaravelCrudWizard\\Providers\\ValidationServiceProvider instead of Illuminate\\Validation\\ValidationServiceProvider::class if you are using illuminate/validation < 11.44.1\n\n### References\nhttps://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4","published":"2025-03-12T15:56:23Z","modified":"2026-09-10T03:50:57.012590110Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"macropay-solutions/laravel-crud-wizard-free","fixedVersion":"3.4.17"}],"fix":{"url":"https://github.com/macropay-solutions/laravel-crud-wizard-free/commit/5c268cc930ec23a2e6761878cc57c6bd1d1889d2","label":"macropay-solutions/laravel-crud-wizard-free@5c268cc"},"references":[{"type":"WEB","url":"https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4"},{"type":"WEB","url":"https://github.com/macropay-solutions/laravel-crud-wizard-free/security/advisories/GHSA-3wgq-h4fr-cwg5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-27515"},{"type":"WEB","url":"https://github.com/macropay-solutions/laravel-crud-wizard-free/commit/5c268cc930ec23a2e6761878cc57c6bd1d1889d2"},{"type":"PACKAGE","url":"https://github.com/macropay-solutions/laravel-crud-wizard-free"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:57.012590110Z"}}