Laravel Flaw Exposes 600 Apps to Remote Code Attacks
A critical Laravel flaw exposes 600 apps to remote code execution by leaking APP_KEY values, according to recent research by GitGuardian and Synacktiv. Since 2018, attackers have accessed over 260,000 APP_KEYs from public GitHub repositories, enabling exploitation across multiple Laravel versions. The flaw stems from Laravel’s decrypt() function, which automatically deserializes data without validation. Malicious […]
