216.73.216.233

CVE-2026-4809

· Published 26/03/2026 11:16 · Modified 26/03/2026 15:13

Labels: CVE-2026-4809 2026-03-26309f9ea4-e3e9-4c6c-b79d-e8eb01244f2cCVE-2026-4809CWE-434

Essential information

Published
26/03/2026 11:16
Modified
26/03/2026 15:13
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored in a web-accessible and executable location, this may lead to remote code execution. At the time of publication, no patch was available and the vendor had not responded to coordinated disclosure attempts.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
NVD
View on NVD

Affected products (CPE)

ProductCPE
plank / laravel-mediable cpe:2.3:a:plank:laravel-mediable:<6.4.0:*:*:*:*:*:*:*

References