Critical severity9.8NVD Advisory· Published Mar 26, 2026· Updated Aug 10, 2026
CVE-2026-4809
CVE-2026-4809
Description
plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=6.4.0+ 1 more
- (no CPE)range: <=6.4.0
- (no CPE)range: <= 6.4.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.