CVE-2026-4809: Plank Laravel-Mediable

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.

Affected products

  • Plank Laravel-Mediable: up to and including 6.4.0

Published 2026-03-26. Last modified 2026-08-10.