CVE-2024-47186
PHP vulnerability analysis and mitigation

Overview

Filament, a collection of full-stack components for Laravel development, was found to contain a cross-site scripting (XSS) vulnerability identified as CVE-2024-47186. The vulnerability affects versions from v3.0.0 through v3.2.114, where improper validation of values passed to ColorColumn or ColumnEntry components could lead to XSS attacks. The issue was discovered on September 25, 2024, and was patched with the release of version 3.2.115 on September 27, 2024 (Vendor Advisory).

Technical details

The vulnerability stems from insufficient validation of color values in the ColorColumn and ColorEntry components. When invalid color values containing specific characters are supplied, the application becomes vulnerable to XSS attacks due to Laravel not escaping special characters within the @style Blade directive. The vulnerability has been assigned a CVSS v3.1 base score of 6.1 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network accessibility with required user interaction (NVD).

Impact

When exploited, this vulnerability allows attackers to execute malicious client-side scripts on pages where the affected color column or entry is rendered. This could result in unauthorized actions, data theft, or other harmful consequences for users who interact with the affected web pages. The attack surface is particularly concerning given Filament's widespread use in Laravel development (Security Online).

Exploitability

The vulnerability can be exploited by passing malicious values such as 'blue;">alert('There's a security problem here')' to the ColorColumn or ColumnEntry components. Since Laravel does not escape special characters within the @style Blade directive, this allows arbitrary JavaScript execution if stored in the database (Vendor Advisory).

Mitigation and workarounds

The vulnerability has been patched in Filament version 3.2.115 by implementing proper escaping of special characters in inline styles. Developers are strongly advised to upgrade to this version immediately. Additionally, the Filament team has published enhanced color validation documentation to help developers implement proper input validation, particularly for applications using the ColorPicker form component (Vendor Advisory).

Community reactions

Security researcher @sv-LayZ is credited with responsibly disclosing the vulnerability, enabling the Filament team to address the issue before potential exploitation. The vulnerability was initially reported for ColorColumn on September 25, 2024, and during the review process, it was discovered that ColorEntry was also affected, leading to a comprehensive fix (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54493HIGH7.7
  • PHP logoPHP
  • phanan/koel
NoYesAug 19, 2026
CVE-2026-54491HIGH7.1
  • PHP logoPHP
  • phanan/koel
NoYesAug 19, 2026
CVE-2026-61807MEDIUM6.3
  • PHP logoPHP
  • snipe/snipe-it
NoYesAug 19, 2026
CVE-2026-54494MEDIUM5.3
  • PHP logoPHP
  • phanan/koel
NoYesAug 19, 2026
CVE-2026-54492MEDIUM4.3
  • PHP logoPHP
  • phanan/koel
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management