CVE-2026-4809
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 1.28%
- 67th pct
- KEV
- No
- Class
- oss containerizable
- CWE-434
Description
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.
References
Status: profiled · ingested 2026-08-10T18:00:50.000Z