CVE-2026-49972: Unrestricted Upload of File with Dangerous Type in plank laravel-mediable
Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any filename containing .php as PHP, the stored file is interpreted as executable code while all MIME type, extension, and aggregate type validation checks pass due to the outer .jpg extension.
AI Analysis
Technical Summary
The vulnerability in Laravel-Mediable prior to version 7.0.0 arises from improper handling of uploaded filenames containing double extensions. The PATHINFO_FILENAME extraction retains the inner .php extension in the base filename, which can be exploited on web servers configured to execute any file with .php in its name as PHP code. Attackers can upload malicious files disguised with an additional safe extension (e.g., .jpg), bypassing validation checks and enabling remote code execution without authentication.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary PHP code on affected servers, potentially leading to full system compromise. The vulnerability depends on server misconfiguration where files with .php anywhere in the filename are executed as PHP scripts. This can result in unauthorized access, data theft, or further attacks on the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should ensure their web servers do not execute PHP code in files with double extensions or filenames containing .php beyond the expected extension. Implement strict server-side validation and configuration to reject or safely handle files with multiple extensions. Consider restricting file upload types and verifying file contents beyond extension checks.
CVE-2026-49972: Unrestricted Upload of File with Dangerous Type in plank laravel-mediable
Description
Laravel-Mediable before 7.0.0 contains a file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading a file with an embedded PHP extension disguised within a double extension such as shell.php.jpg. The PATHINFO_FILENAME extraction preserves the inner .php extension in the base name, and on misconfigured Apache or nginx servers that execute any filename containing .php as PHP, the stored file is interpreted as executable code while all MIME type, extension, and aggregate type validation checks pass due to the outer .jpg extension.
CVSS v4.0
Score 7.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Laravel-Mediable prior to version 7.0.0 arises from improper handling of uploaded filenames containing double extensions. The PATHINFO_FILENAME extraction retains the inner .php extension in the base filename, which can be exploited on web servers configured to execute any file with .php in its name as PHP code. Attackers can upload malicious files disguised with an additional safe extension (e.g., .jpg), bypassing validation checks and enabling remote code execution without authentication.
Potential Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary PHP code on affected servers, potentially leading to full system compromise. The vulnerability depends on server misconfiguration where files with .php anywhere in the filename are executed as PHP scripts. This can result in unauthorized access, data theft, or further attacks on the affected system.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should ensure their web servers do not execute PHP code in files with double extensions or filenames containing .php beyond the expected extension. Implement strict server-side validation and configuration to reject or safely handle files with multiple extensions. Consider restricting file upload types and verifying file contents beyond extension checks.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-02T16:30:15.234Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a552f7368715ace43a5ece3
Added to database: 07/13/2026, 18:33:23 UTC
Last enriched: 07/21/2026, 18:44:51 UTC
Last updated: 08/27/2026, 10:52:09 UTC
Views: 94
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.