Laravel Valet versions 1.1.4 to 2.0.3 contain a local privilege escalation vulnerability that allows users to modify the valet command with root privileges. Attackers can edit the symlinked valet command to execute arbitrary code with root permissions without additional authentication.
References
Configurations
No configuration.
History
16 Jan 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-16 00:16
Updated : 2026-01-16 15:55
NVD link : CVE-2021-47756
Mitre link : CVE-2021-47756
CVE.ORG link : CVE-2021-47756
JSON object : View
Products Affected
No product.
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
