CVE-2026-48067: Filamentphp Filament

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelectOptionsQuery() method may be used to scope the options available in the Select field for AttachAction and AssociateAction. However, the built-in validation rule for these fields did not apply the same scope. As a result, a user who can trigger these actions could tamper with the Livewire component's state and submit an out-of-scope value. This vulnerability is fixed in filament/actions 4.11.4 and 5.6.4 and filament/tables 3.3.51.

Affected products

  • Filamentphp Filament: from 4.0.0, before 4.11.4 (fixed in 4.11.4); from 5.0.0, before 5.6.4 (fixed in 5.6.4); from 3.0.0, before 3.3.51 (fixed in 3.3.51)

Published 2026-06-22. Last modified 2026-06-23.