# CVE-2025-27515

## Summary

- **CVE ID:** CVE-2025-27515
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-155
- **Published:** Mar 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1.

## Affected Products

- laravel — framework (>= 12.0.0, < 12.1.1)
- laravel — framework (< 11.44.1)

## References

- [CNA](https://github.com/laravel/framework/security/advisories/GHSA-78fx-h6xr-vch4)
- [CNA](https://github.com/laravel/framework/commit/2d133034fefddfb047838f4caca3687a3ba811a5)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.73%
- **EPSS Percentile:** 52.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._