LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.
History

Wed, 11 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Laradashboard lara Dashboard
CPEs cpe:2.3:a:laradashboard:lara_dashboard:*:*:*:*:*:laravel:*:*
Vendors & Products Laradashboard lara Dashboard
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 05 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Laradashboard
Laradashboard laradashboard
Vendors & Products Laradashboard
Laradashboard laradashboard

Thu, 04 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Description LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow trusts the Host header, allowing attackers to redirect the administrator’s reset token to an attacker-controlled server. This can be combined with the module installation process to automatically execute the ServiceProvider::boot() method, enabling arbitrary PHP code execution.
Title LaraDashboard: 1-Click Pre-Auth RCE via Host Header + Module Installation Chain
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-04T22:10:26.848Z

Updated: 2025-12-05T15:23:58.141Z

Reserved: 2025-12-03T15:12:22.978Z

Link: CVE-2025-66509

cve-icon Vulnrichment

Updated: 2025-12-05T15:23:54.151Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-04T22:15:49.673

Modified: 2026-03-11T15:58:32.010

Link: CVE-2025-66509

cve-icon Redhat

No data.