Description
Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient integrity protection, while an unsafe legacy unserialize() fallback remains reachable. An attacker who can manipulate database records, such as through a separate SQL injection or compromised administrative access, can insert a malicious serialized object graph containing executable closure behavior; visiting the associated magic link then deserializes the record and can execute arbitrary code in the application process. The affected path is restricted to manipulated action records and does not independently provide database-write access. This issue is fixed in version 2.25.1.
Published: 2026-09-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Laravel MagicLink versions 2.0.0 through 2.25.1 serialize arbitrary action objects into a database column without integrity protection and use PHP’s unserialize(), creating a classic serialization vulnerability (CWE-502). A crafted serialized object graph that contains a PHP Closure can be injected, and when a user opens the corresponding magic link the framework deserializes the record and executes the closure, resulting in arbitrary PHP code execution in the application context. This undermines confidentiality, integrity, and availability.

Affected Systems

The affected product is cesargb:laravel-magiclink. Versions 2.0.0 through 2.25.1 are vulnerable; the issue is resolved in 2.25.1. An attacker who can alter rows in the magic_links.action column, such as via SQL injection or compromised administrative credentials, can insert a malicious serialized payload that triggers the unsafe deserialization when the magic link is visited.

Risk and Exploitability

The CVSS score of 8.8 classifies this exploit as high severity. The EPSS score indicates a very low exploitation probability of less than 1% (approximately 0.5%), and the vulnerability is not listed in CISA’s KEV catalog. The attack vector requires the attacker to have the ability to insert or modify database rows, such as through a separate SQL injection flaw or compromised administrative credentials; once a malicious record is in place, simply visiting the magic link will trigger deserialization and execute arbitrary code. Because the flaw does not grant write access on its own, the overall risk hinges on the likelihood of database manipulation, making it database access controls.

Generated by OpenCVE AI on September 21, 2026 at 00:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade cesargb:laravel-magiclink to version 2.25.1 or later, which removes the insecure serialization path and disables the legacy unserialize fallback.
  • Ensure that database accounts used by the application have the least privilege possible and monitor for SQL injection activity that could allow row manipulation.
  • If upgrading is not immediately possible, delete or sanitize existing records in the magic_links table that may contain untrusted serialized payloads, and enforce server‑side validation to reject any future malicious data.
  • Apply additional controls such as external input to prevent similar issues in the future.

Generated by OpenCVE AI on September 21, 2026 at 00:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cesargb
Cesargb laravel-magiclink
Vendors & Products Cesargb
Cesargb laravel-magiclink

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and src/Actions/ResponseAction.php without sufficient integrity protection, while an unsafe legacy unserialize() fallback remains reachable. An attacker who can manipulate database records, such as through a separate SQL injection or compromised administrative access, can insert a malicious serialized object graph containing executable closure behavior; visiting the associated magic link then deserializes the record and can execute arbitrary code in the application process. The affected path is restricted to manipulated action records and does not independently provide database-write access. This issue is fixed in version 2.25.1.
Title Laravel MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Cesargb Laravel-magiclink
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:49:19.880Z

Reserved: 2026-07-10T18:51:13.919Z

Link: CVE-2026-61701

cve-icon Vulnrichment

Updated: 2026-09-14T18:49:16.347Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T17:17:49.613

Modified: 2026-09-30T19:08:43.927

Link: CVE-2026-61701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data