plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored in a web-accessible and executable location, this may lead to remote code execution. At the time of publication, no patch was available and the vendor had not responded to coordinated disclosure attempts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-03-26 11:16
Updated : 2026-03-26 15:13
NVD link : CVE-2026-4809
Mitre link : CVE-2026-4809
CVE.ORG link : CVE-2026-4809
JSON object : View
Products Affected
No product.
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
