PatchSiren

SpartnerNL CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SpartnerNL CVE published 2026-09-01

CVE-2026-84374

The Laravel Excel package, used for supercharged Excel exports and imports in Laravel applications, is vulnerable to a path traversal issue. This vulnerability exists from version 3.1.8 to 3.1.69 and allows an attacker to overwrite arbitrary existing files with export content by manipulating the export path. The issue arises from the Maatwebsite/Excel/Files/Disk::copy() method resolving the $destination p [truncated]