PatchSiren cyber security CVE debrief
CVE-2026-48067 filamentphp CVE debrief
CVE-2026-48067 is a vulnerability in Filament, a collection of full-stack components for accelerated Laravel development. The vulnerability affects filament/actions versions 4.0.0 to 4.11.4 and 5.6.4, and filament/tables versions 3.0.0 to 3.3.51. An attacker who can trigger the AttachAction and AssociateAction could tamper with the Livewire component's state and submit an out-of-scope value due to a discrepancy between the recordSelectOptionsQuery() method and the built-in validation rule. This issue is fixed in filament/actions versions 4.11.4 and 5.6.4, and filament/tables version 3.3.51.
- Vendor
- filamentphp
- Product
- filament
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-22
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-22
- Advisory updated
- 2026-06-23
Who should care
Developers and administrators using Filament for Laravel development should be aware of this vulnerability and take immediate action to update their dependencies to the patched versions. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM, indicating a moderate level of risk.
Technical summary
The vulnerability arises from the recordSelectOptionsQuery() method in filament/actions and filament/tables, which allows scoping of options for the Select field in AttachAction and AssociateAction. However, the built-in validation rule for these fields does not apply the same scope, enabling an attacker to submit an out-of-scope value. The issue is addressed in filament/actions versions 4.11.4 and 5.6.4, and filament/tables version 3.3.51.
Defensive priority
Apply updates to filament/actions and filament/tables to the patched versions as soon as possible. Review and monitor your application's usage of AttachAction and AssociateAction to detect potential exploitation attempts.
Recommended defensive actions
- Update filament/actions to version 4.11.4 or later
- Update filament/actions to version 5.6.4 or later
- Update filament/tables to version 3.3.51 or later
- Review application code for custom usage of recordSelectOptionsQuery() method
- Monitor application logs for suspicious activity related to AttachAction and AssociateAction
Evidence notes
The CVE record and NVD detail provide official information about the vulnerability. The source item URL provides additional context from the NVD database. The reference to the GitHub security advisory offers further details on the vulnerability and its fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48067 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48067
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48067 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48067
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/filamentphp/filament/security/advisories/GHSA-7q3w-xqjw-g3cr
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.