PatchSiren

plank CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH plank CVE published 2026-07-13

CVE-2026-49972

CVE-2026-49972 is a high-severity vulnerability in Laravel-Mediable that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension. This vulnerability exists in versions before 7.0.0 and can be exploited on misconfigured Apache or nginx servers that execute PHP code in uploaded files. The vulnerability has a CVS [truncated]

HIGH plank CVE published 2026-07-13

CVE-2026-49970

CVE-2026-49970 is a path traversal vulnerability in Laravel-Mediable before 7.0.0. The vulnerability exists in the File::sanitizePath() function, which allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). This enables remote code execution in sensitive locations such as the document root, environment configuration f [truncated]

MEDIUM plank CVE published 2026-07-13

CVE-2026-49969

CVE-2026-49969 is a server-side request forgery vulnerability in Laravel-Mediable before 7.0.0. The vulnerability allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). This can lead to unauthorized access to internal infrastructure, sensitive file retrieval, and exfiltration of cloud cred [truncated]

CRITICAL plank CVE published 2026-03-26

CVE-2026-4809

**CVE-2026-4809** is a critical unpatched vulnerability in `plank/laravel-mediable` through version 6.4.0 that enables arbitrary file upload with potential remote code execution. The flaw occurs when applications using this package accept or prefer client-supplied MIME types during file upload handling, allowing attackers to bypass file type validation by submitting PHP executable code with a declared ben [truncated]