CVE-2026-49969: Plank Laravel-Mediable

High severity, CVSS 7.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can craft URLs targeting RFC-1918 addresses, loopback interfaces, cloud metadata endpoints, or file:// URIs through RemoteUrlAdapter to reach internal infrastructure, retrieve sensitive files, and exfiltrate cloud credentials such as IAM tokens from instance metadata services.

Affected products

  • Plank Laravel-Mediable: before 7.0.0 (fixed in 7.0.0)

Published 2026-07-13. Last modified 2026-07-15.