Vendor
The Laravel Excel library (v3.1.8-v3.1.69) fails to properly sanitize the destination path in the store() method, allowing an attacker to overwrite arbitrary files writable by the PHP process via path traversal, leading to potential RCE.