Impact
Laravel MagicLink versions 2.0.0 through 2.25.1 serialize arbitrary action objects into a database column without integrity protection and use PHP’s unserialize(), creating a classic serialization vulnerability (CWE-502). A crafted serialized object graph that contains a PHP Closure can be injected, and when a user opens the corresponding magic link the framework deserializes the record and executes the closure, resulting in arbitrary PHP code execution in the application context. This undermines confidentiality, integrity, and availability.
Affected Systems
The affected product is cesargb:laravel-magiclink. Versions 2.0.0 through 2.25.1 are vulnerable; the issue is resolved in 2.25.1. An attacker who can alter rows in the magic_links.action column, such as via SQL injection or compromised administrative credentials, can insert a malicious serialized payload that triggers the unsafe deserialization when the magic link is visited.
Risk and Exploitability
The CVSS score of 8.8 classifies this exploit as high severity. The EPSS score indicates a very low exploitation probability of less than 1% (approximately 0.5%), and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires the attacker to have the ability to insert or modify database rows, such as through a separate SQL injection flaw or compromised administrative credentials; once a malicious record is in place, simply visiting the magic link will trigger deserialization and execute arbitrary code. Because the flaw does not grant write access on its own, the overall risk hinges on the likelihood of database manipulation, making it database access controls.
OpenCVE Enrichment