CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-4809

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
1.28%
67th pct
KEV
No
Class
oss containerizable
CWE-434

Description

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.

References

Status: profiled · ingested 2026-08-10T18:00:50.000Z