CVE-2025-27515 affects the Laravel web application framework. When an application uses wildcard validation rules for file or image array inputs, such as files.*, a user can craft a malicious request that bypasses the intended validation logic for those uploaded items. As a result, Laravel may incorrectly accept files that should have been rejected under the configured validation rules. The issue specifically concerns validation of file or image fields supplied as arrays via wildcard matching rather than per-file validation. Fixed versions include Laravel 10.48.29, 11.44.1, and 12.1.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
files.* for security-sensitive file or image validation. Apply explicit server-side validation to each uploaded file, enforce strict allowlists for MIME types and extensions, verify content where appropriate, and ensure uploaded files are stored and served in a manner that prevents execution or unsafe processing.Patch, then assume compromise.
laravel/framework to a fixed version: 10.48.29 or later on the 10.x branch, 11.44.1 or later on the 11.x branch, or 12.1.1 or later on the 12.x branch. Review application code that relies on wildcard validation for uploaded file arrays and confirm that each uploaded file is validated as intended after upgrading.2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a practical proof-of-concept for CVE-2025-27515, a file upload validation bypass vulnerability in Laravel Framework (<= 12.0.0). The repository contains a full Laravel application with a vulnerable file upload endpoint (app/Http/Controllers/UploadController.php) that uses wildcard validation ('files.*'), allowing attackers to upload files that bypass intended restrictions. The exploit (exploit.py) is a Python script that crafts and uploads a polyglot JPEG+PHP file, which passes validation and is stored in a web-accessible directory. The payload is a simple PHP web shell that enables remote code execution via HTTP requests. The repository includes all necessary files to run the vulnerable application and demonstrates the attack end-to-end. The main attack vector is network-based, targeting the /upload HTTP endpoint, and the exploit is operational, providing a working RCE payload. No evidence of fake or detection-only code is present; this is a real exploit for educational and authorized testing purposes.
This repository is a comprehensive proof-of-concept (PoC) for CVE-2025-27515, a file upload validation bypass in Laravel Framework (≤ 12.0.0) when using wildcard validation (e.g., 'files.*'). The repository contains a full Laravel application intentionally configured to be vulnerable, as well as two exploit scripts: one in Python (exploit.py) and one in Rust (exploit-rs/src/main.rs). The exploit works by crafting a polyglot file that is both a valid JPEG and a PHP webshell, bypassing MIME type and extension checks. The exploit scripts automate the process of obtaining a CSRF token, uploading the malicious file to the /upload endpoint, and reporting the result. The vulnerable code is in app/Http/Controllers/UploadController.php, which uses insufficient validation on file uploads. The repository is structured as a typical Laravel project, with additional exploit scripts and clear documentation in the README.md. The main attack vector is network-based, targeting the /upload HTTP endpoint. The exploit provides a working webshell if successful, allowing remote command execution via the uploaded file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.