High severity7.4NVD Advisory· Published May 29, 2026· Updated Jul 22, 2026
CVE-2026-48555
CVE-2026-48555
Description
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
spatie/laravel-medialibraryPackagist | < 11.23.0 | 11.23.0 |
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <11.23.0
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-fggg-964j-3j7hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-48555ghsaADVISORY
- github.com/spatie/laravel-medialibrary/commit/608ea03703d3887c46434f5dda6af56de6346abanvdWEB
- github.com/spatie/laravel-medialibrary/pull/3939nvdWEB
- github.com/spatie/laravel-medialibrary/releases/tag/11.23.0nvdWEB
- www.vulncheck.com/advisories/spatie-laravel-media-library-ssrf-via-addmediafromurlnvdWEB
News mentions
0No linked articles in our index yet.