Be part of JetBrains PHPverse 2026 on June 9 – a free online event bringing PHP devs worldwide together.

mbarb's avatar
Level 3

PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution

Hi, ExploitDB just released a vulnerability PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution. How this affects our installations and how can we mitigate.

Thanks Manos

0 likes
2 replies
Nash's avatar
Nash
Best Answer
Level 20

This issue has already been addressed. If you are using an up-to-date version of Laravel and you don't use cookie serialization, you should be in the clear. The vulnerability also needs the app key to be exploited.

https://laravel.com/docs/5.5/upgrade#upgrade-5.5.42

Please or to participate in this conversation.