Laravel Valet 2.0.3 - Local Privilege Escalation (macOS)
Vulnerability Description
Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47756
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- leonjza
Affected Vendor
Laravel
View all reports →