CVE-2026-84374 | SpartnerNL Laravel Excel up to 3.1.69 Disk src/Files/Disk.php copy destination path traversal
A vulnerability labeled as critical has been found in SpartnerNL Laravel Excel up to 3.1.69. The impacted element is the function MaatwebsiteExcelFilesDisk::copy of the file src/Files/Disk.php of the component Disk. The manipulation of the argument destination results in path traversal.
This vulnerability is reported as CVE-2026-84374. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.VulDB Recent EntriesRead More