Impact
Maravel, a PHP framework oriented toward dependency injection, contains a flaw in its route handling logic. When a dynamic route template such as "/api/v1/users/{id}" is compiled, the raw placeholder name is incorrectly added to a flat static route list. If an attacker supplies a request that includes the literal brace syntax, the request bypasses the dynamic route engine and causes PHP 8+ to throw an ArgumentCountError, resulting in a 500 Internal Server Error instead of the expected 404. The varying error responses provide an error‑oracle side‑channel that allows the attacker to determine which route patterns trigger the error, revealing internal parameter names, controller mappings, and application structure (CWE‑203).
Affected Systems
The vulnerability is present in Maravel framework versions prior to 10.73.1. Users deploying these versions on PHP 8 or newer are at risk. Version 10.73.1 and later contain the vendor patch, and the package is distributed under macropay-solutions/maravel-framework.
Risk and Exploitability
With a CVSS score of 6.9 the issue is considered moderate severity. No EPSS value is available, and the vulnerability is not listed in CISA KEV, indicating that widespread exploitation has not been reported. The attack requires only automated HTTP fuzzing of exposed endpoints and does not need privileged access. An adversary can use the response type difference to map application routes, which may assist in locating sensitive endpoints for subsequent attacks.
OpenCVE Enrichment