Unrated severityNVD Advisory· Published Jul 13, 2026· Updated Jul 15, 2026
Laravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling
CVE-2026-49969
Description
Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can craft URLs targeting RFC-1918 addresses, loopback interfaces, cloud metadata endpoints, or file:// URIs through RemoteUrlAdapter to reach internal infrastructure, retrieve sensitive files, and exfiltrate cloud credentials such as IAM tokens from instance metadata services.
Affected products
1- Range: <7.0.0
Patches
Vulnerability mechanics
References
3- github.com/plank/laravel-mediable/commit/7e9e3000fa05fe16e678f15bfb51a091e60c2cb8mitrepatch
- github.com/plank/laravel-mediable/releases/tag/7.0.0mitrerelease-notespatch
- www.vulncheck.com/advisories/laravel-mediable-ssrf-via-remoteurladapter-url-handlingmitrethird-party-advisory
News mentions
0No linked articles in our index yet.