hunt-laravel
Installation
SKILL.md
HUNT-LARAVEL — Laravel Specific Vulnerabilities
Crown Jewel Targets
Laravel debug mode enabled in production = instant RCE via Ignition (CVE-2021-3129).
Highest-value findings:
- Ignition RCE (CVE-2021-3129) —
APP_DEBUG=true+ Laravel < 8.4.2 →/_ignition/execute-solutionRCE without auth - Telescope dashboard —
/telescopeexposes full request/response logs, DB queries, Redis commands, scheduled jobs, environment variables - Horizon dashboard —
/horizonexposes queue job details, failed jobs with full payloads (may contain API keys, PII) - Signed URL manipulation — if
URL::signedRoutevalidates wrong params → bypass signed URL → unauthorized actions - .env exposure —
APP_KEYleaked → decrypt all encrypted cookies → forge session → ATO