Vulnerability DatabaseGHSA-69rh-hccr-cxrj

GHSA-69rh-hccr-cxrj
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-69rh-hccr-cxrj) was identified in the Laravel Rest API package (lomkit/laravel-rest-api) affecting versions prior to 2.13.0. This search validation bypass vulnerability was discovered and disclosed on May 25, 2025, with an update published to the GitHub Advisory Database on May 27, 2025. The vulnerability received a CVSS score of 6.6 (Moderate severity) and was assigned CVE-2025-48490 (GitHub Advisory).

Technical details

The vulnerability stems from a flaw in how the framework handles multiple validation rules for the same attribute across different contexts (index, store, and update actions). The issue occurs when multiple validations defined for the same attribute could be silently overridden, allowing malicious actors to bypass expected validation rules. The vulnerability is characterized by a Network attack vector with Low attack complexity, requiring No privileges or user interaction for exploitation (GitHub Advisory).

Impact

The vulnerability could lead to unauthorized data being accepted or processed by the API, depending on the context in which the validation was bypassed. According to the CVSS metrics, while there is no impact on confidentiality and availability, the vulnerability poses a High integrity impact on the vulnerable system (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 2.13.0 of the Laravel Rest API package. The fix was implemented through PR #172, which ensures that multiple rule definitions are merged correctly rather than being overwritten. Users should upgrade to version 2.13.0 or later to mitigate this vulnerability (GitHub Advisory, GitHub PR).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
David EstlickCISO
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
Adam FletcherChief Security Officer
“We know that if Wiz identifies something as critical, it actually is.”
Greg PoniatowskiHead of Threat and Vulnerability Management