CVE-2026-48555: Spatie Laravel-Medialibrary
High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.
Affected products
- Spatie Laravel-Medialibrary: before 11.23.0 (fixed in 11.23.0)
Published 2026-05-29. Last modified 2026-10-08.