Intel

AIKIDO-2026-10659

laravel/framework is vulnerable to Insufficient Verification of Data Authenticity

Insufficient Verification of Data Authenticity Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

75

High Risk

This Affects:

PHPlaravel/framework
5.6.0 - 12.56.0
Fixed in 12.57.0
13.0.0 - 13.6.0
Fixed in 13.7.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package allow attackers to bypass signed URL validation by sending the expires query parameter as an array. The expiry comparison silently fails, treating the URL as never expired. Captured signed URLs can therefore be replayed past their intended expiration.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

laravel/framework is vulnerable to Insufficient Verification of Data Authenticity in versions 5.6.0 - 12.56.0 and 13.0.0 - 13.6.0.

How to fix this

Upgrade the laravel/framework library to the patch version.