# Laravel framework versions 12.x and 13.x contain a security policy bypass vulnerability…

Published: 2026-06-01 · Severity: high
Canonical: https://vorant.io/reports/29d9076e-83e3-449a-a980-80aaad5c9211/laravel-framework-versions-12-x-and-13-x-contain-a-security-policy-bypass

> Laravel framework versions 12.x and 13.x contain a security policy bypass vulnerability (CVE-2026-48019) requiring immediate patching to v12.60.0+ or v13.10.0+.

A security policy bypass vulnerability has been identified in the Laravel PHP framework affecting multiple version branches. The flaw impacts Laravel framework versions 12.x prior to 12.60.0 and versions 13.x prior to 13.10.0. An attacker can exploit this vulnerability to circumvent security controls within affected Laravel applications.

The French national CERT (CERT-FR) has published an advisory recommending immediate remediation. Organizations running vulnerable Laravel framework versions should prioritize upgrading to the patched releases. The vendor has addressed the issue in Laravel framework versions 12.60.0 and 13.10.0.

Given Laravel's widespread use in web application development, this vulnerability could affect numerous production systems. Organizations should inventory Laravel deployments, identify vulnerable versions, and apply patches according to their change management processes. The security policy bypass nature of this flaw suggests potential for privilege escalation or unauthorized access in affected applications.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48019

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0670

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/29d9076e-83e3-449a-a980-80aaad5c9211/laravel-framework-versions-12-x-and-13-x-contain-a-security-policy-bypass.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
