Product
high
advisory
Server-Side Request Forgery in Laravel-Mediable Allows Credential Exfiltration
4 rules 4 TTPs 1 CVEA Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-49969, exists in Laravel-Mediable versions prior to 7.0.0, allowing remote attackers to force the server to make arbitrary HTTP requests to attacker-controlled URLs provided to `MediaUploader::fromSource()` to target internal network resources, access sensitive files, and exfiltrate cloud credentials like IAM tokens.
Laravel-Mediable
ssrf
vulnerability
web-application
credential-access
data-exfiltration
4r
4t
1c
critical
advisory
Laravel Mediable Arbitrary File Upload Vulnerability (CVE-2026-4809)
2 rules 2 TTPsplank/laravel-mediable through version 6.4.0 is vulnerable to arbitrary file upload via client-supplied MIME types, potentially leading to remote code execution if the uploaded file is stored in a web-accessible location.
laravel-mediable
file-upload
rce
CVE-2026-4809
2r
2t