


Perceptive Security
SOC/SIEM Consultancy

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplieā¦
Published:
25 maart 2026 om 23:00:00
Alert date:
26 maart 2026 om 16:11:28
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
CVE-2026-4809 affects plank/laravel-mediable through version 6.4.0, allowing dangerous file type uploads when applications accept client-supplied MIME types. Remote attackers can submit executable PHP code while declaring benign image MIME types, leading to arbitrary file upload. If uploaded files are stored in web-accessible and executable locations, this enables remote code execution. No patch is currently available and the vendor has not responded to disclosure attempts.
Technical details
Mitigation steps:
Affected products:
plank/laravel-mediable
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4809
https://github.com/plank/laravel-mediable
https://github.com/plank/laravel-mediable/releases/tag/6.4.0
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
