Security Advisory

CVE-2026-4809

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-03-26 11:03:27
Last updated 2026-08-10 11:43:52
Assigner TuranSec
CVSS score 10.0
State PUBLISHED

Description

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.