Laravel Passport OAuth2 RSA private or public keys are publicly accessible at default storage paths. Exposed private keys allow attackers to forge OAuth2 access tokens and impersonate any user.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view