CVE-2026-48555: Spatie Laravel-Medialibrary

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.

Affected products

  • Spatie Laravel-Medialibrary: before 11.23.0 (fixed in 11.23.0)

Published 2026-05-29. Last modified 2026-10-08.