#Laravel
All CosmicBytez Labs articles tagged #Laravel, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-73683: Laravel Socialite Facebook OIDC Authentication Bypass
Laravel Socialite's Facebook provider is vulnerable to OIDC id_token replay attacks due to missing nonce validation in getUserByOIDCToken().
- Security
CVE-2026-41452: Krayin CRM Admin Account Takeover via Installer Middleware Bypass
A critical missing authentication vulnerability in Krayin CRM 2.2.4 allows unauthenticated attackers to overwrite the primary administrator account by...
- News
Laravel Lang Packages Hijacked to Deploy
A supply chain attack targeting Laravel Lang localization packages has exposed developers to credential-stealing malware after attackers abused GitHub...
- News
Laravel-Lang PHP Packages Compromised to Deliver
Multiple PHP packages belonging to the Laravel-Lang organization have been poisoned in a software supply chain attack, delivering a cross-platform...
- Security
CVE-2025-54068: Laravel Livewire Code Injection
A critical code injection vulnerability in Laravel Livewire v3 allows unauthenticated remote attackers to execute arbitrary commands. Over 130,000...