← Vulnerability feed

Vulnerability record · CVE-2021-43617 · published 14 November 2021

CVE-2021-43617: Laravel framework unrestricted file upload vulnerability

Laravel · Framework

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

9.8 CVSS 3.1 Critical EPSS 20% · top 2.7% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Validation/Concerns/ValidatesAttributes.php lacks a check for .phar files, which are handled as application/x-httpd-php on systems based on Debian. NOTE: this CVE Record is for Laravel Framework, and is unrelated to any reports concerning incorrectly written user applications for image upload.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-43617 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-19316Laravel framework os command injection vulnerabilityOS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.EPSS 2.5%8.8CVE-2018-6330Laravel framework sql injection vulnerabilityLaravel 5.4.15 is vulnerable to Error based SQL injection in save.php via dhx_user and dhx_version parameters.EPSS 1.6%8.7CVE-2024-52301Laravel framework argument injection alters request environmentLaravel mishandles the register_argc_argv PHP directive: when that directive is on, a crafted query string on any URL can inject argv values that cha…EPSS 45%analysed6.9CVE-2025-27515Laravel framework vulnerabilityLaravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious …EPSS 0.73%6.1CVE-2024-13919Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of route para…EPSS 0.52%6.1CVE-2024-13918Laravel framework cross-site scripting vulnerabilityThe Laravel framework versions between 11.9.0 and 11.35.1 are susceptible to reflected cross-site scripting due to an improper encoding of request pa…EPSS 0.59%6.1CVE-2021-43808Laravel framework cross-site scripting vulnerabilityLaravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-site scripting (XSS) vulnerabi…EPSS 0.80%5.3CVE-2022-40482Laravel framework observable discrepancy vulnerabilityThe authentication method in Laravel 8.x through 9.x before 9.32.0 was discovered to be vulnerable to user enumeration via timeless timing attacks wi…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2021-43617), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.