MEDIUM
GHSA-3wgq-h4fr-cwg5
laravel-crud-wizard-free has File Validation Bypass
Quick fix
GHSA-3wgq-h4fr-cwg5 — macropay-solutions/laravel-crud-wizard-free: upgrade to the fixed version with the command below.
composer require macropay-solutions/laravel-crud-wizard-free:^3.4.17Details
### Impact Medium
### Patches Version 3.4.17 fixes illuminate/validation v 8.0.0 to 11.44.0
### Workarounds Register \MacropaySolutions\LaravelCrudWizard\Providers\ValidationServiceProvider instead of Illuminate\Validation\ValidationServiceProvider::class if you are using illuminate/validation < 11.44.1
### References https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/macropay-solutions/laravel-crud-wizard-free
Introduced in:
0Fixed in: 3.4.17Fix
composer require macropay-solutions/laravel-crud-wizard-free:^3.4.17References
- https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4[WEB]
- https://github.com/macropay-solutions/laravel-crud-wizard-free/security/advisories/GHSA-3wgq-h4fr-cwg5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27515[ADVISORY]
- https://github.com/macropay-solutions/laravel-crud-wizard-free/commit/5c268cc930ec23a2e6761878cc57c6bd1d1889d2[WEB]
- https://github.com/macropay-solutions/laravel-crud-wizard-free[PACKAGE]