CRITICAL9.1
GHSA-qq2h-m2hj-hrff
DevDojo Voyager Argument Injection vulnerability
Details
DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arbitrary OS commands via a specific php artisan command.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/tcg/voyager
Introduced in:
1.4.0No fixed version published yet for tcg/voyager (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-32931[ADVISORY]
- https://github.com/lishihihi/voyager-issue-report[WEB]
- https://github.com/thedevdojo/voyager[PACKAGE]
- https://github.com/thedevdojo/voyager/blob/1.8/docs/core-concepts/compass.md[WEB]
- https://github.com/thedevdojo/voyager/blob/7e7e0f4f0e115d2d9e0481a86153a1ceff194c00/resources/views/compass/includes/commands.blade.php#L11-L16[WEB]