CVE-2025-54082 - CVE House
Back to Database
Status published High CVE-2025-54082

nova-tiptap has an Unauthenticated Arbitrary File Upload Vulnerability

Vulnerability Description

marshmallow-packages/nova-tiptap is a rich text editor for Laravel Nova based on tiptap. Prior to 5.7.0, a vulnerability was discovered in the marshmallow-packages/nova-tiptap Laravel Nova package that allows unauthenticated users to upload arbitrary files to any Laravel disk configured in the application. The vulnerability is due to missing authentication middleware (Nova and Nova.Auth) on the /nova-tiptap/api/file upload endpoint, the lack of validation on uploaded files (no MIME/type or extension restrictions), and the ability for an attacker to choose the disk parameter dynamically. This means an attacker can craft a custom form and send a POST request to /nova-tiptap/api/file, supplying a valid CSRF token, and upload executable or malicious files (e.g., .php, binaries) to public disks such as local, public, or s3. If a publicly accessible storage path is used (e.g. S3 with public access, or Laravel’s public disk), the attacker may gain the ability to execute or distribute arbitrary files — amounting to a potential Remote Code Execution (RCE) vector in some environments. This vulnerability was fixed in 5.7.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54082

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

marshmallow-packages

View all reports →

Affected Software

nova-tiptap
Vulnerable Versions:
< 5.7.0

Timeline

Official Publish: July 21st, 2025
Last Modified: July 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)