GHSA-69rh-hccr-cxrj · Severity: medium · Ecosystem: composer — Laravel Rest Api has a Search Validation Bypass
Laravel Rest Api is an API generator. Prior to version 2.13.0, a validation bypass vulnerability was discovered where multiple validations defined for the same attribute could be silently overridden. Due to how the framework merged validation rules across multiple contexts (such as index, store, and update actions), malicious actors could exploit this behavior by crafting requests that bypass expected validation rules, potentially injecting unexpected or dangerous parameters into the application. This could lead to unauthorized data being accepted or processed by the API, depending on the context in which the validation was bypassed. This issue has been patched in version 2.13.0.
Conclusion & alert: CVE-2025-48490 is rated Moderate Risk (47.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-26 | 0.10% | 0.36% | +0.26% |
| 2 | 2025-10-26 | 0.15% | 0.10% | -0.05% |
| 3 | 2025-09-29 | — | 0.15% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.6 | 4.0 | MEDIUM |
|
— | — | [email protected] |
GHSA-69rh-hccr-cxrj · Severity: medium · Ecosystem: composer — Laravel Rest Api has a Search Validation Bypass
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||