CVE-2026-105125: LaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} Endpoint
LaraDashboard before 1.4.8 contains a path traversal vulnerability that allows unauthenticated attackers to read JSON files by manipulating the {lang} route segment. On Windows hosts, attackers can send URL-encoded backslash sequences like ..%5C to escape resources/lang and read composer.json or other application JSON files.
Affected Software
Event History
Frequently Asked Questions
Which deployments are most exposed?
Windows-hosted LaraDashboard deployments are specifically affected because URL-encoded backslashes such as ..%5C can be used to escape the resources/lang directory. The affected endpoint is reachable without authentication.
What does an attacker need to exploit this issue?
An attacker needs network access to the /api/translations/{lang} endpoint and must craft the lang route segment with path-traversal sequences. Exploitation is unauthenticated, but the high attack complexity indicates that a successful request requires specific path manipulation.
What information could be exposed?
The issue allows reading JSON files outside the intended language-resource directory. The available information specifically identifies composer.json as a potentially readable application file.
How can I determine whether my deployment is affected?
Check whether LaraDashboard is older than 1.4.8 and is running on Windows. Also review access logs for requests to /api/translations/ containing URL-encoded backslashes, particularly ..%5C sequences.