CVE-2026-93352: Unrestricted Upload of File with Dangerous Type in plank laravel-mediable
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
AI Analysis
Technical Summary
The vulnerability in Laravel-Mediable 7.0.0 before 7.0.2 is due to an incomplete patch for a previous issue (CVE-2026-49972). The blocklist of forbidden file extensions in config/mediable.php includes 'phpt' but omits 'pht'. On Debian and Ubuntu systems, Apache executes .pht files as PHP via the default FilesMatch directive. Because 'pht' is not blocked, an attacker can upload a .pht file that passes validation in MediaUploader::verifyExtension() and File::sanitizeFileName(), resulting in the file being saved and executed as PHP code when accessed, enabling remote code execution with the privileges of the web server process.
Potential Impact
Successful exploitation allows an unauthenticated attacker to upload and execute arbitrary PHP code on the server, leading to remote code execution with the privileges of the web server process. This can compromise the affected system's confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Laravel-Mediable version 7.0.2 and later. Users should upgrade to version 7.0.2 or newer to ensure the .pht extension is properly blocked and prevent this vulnerability.
CVE-2026-93352: Unrestricted Upload of File with Dangerous Type in plank laravel-mediable
Description
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
CVSS v4.0
Score 9.3critical
Affected software
plank
laravel-mediable
pkg:github/laravel-mediableRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Laravel-Mediable 7.0.0 before 7.0.2 is due to an incomplete patch for a previous issue (CVE-2026-49972). The blocklist of forbidden file extensions in config/mediable.php includes 'phpt' but omits 'pht'. On Debian and Ubuntu systems, Apache executes .pht files as PHP via the default FilesMatch directive. Because 'pht' is not blocked, an attacker can upload a .pht file that passes validation in MediaUploader::verifyExtension() and File::sanitizeFileName(), resulting in the file being saved and executed as PHP code when accessed, enabling remote code execution with the privileges of the web server process.
Potential Impact
Successful exploitation allows an unauthenticated attacker to upload and execute arbitrary PHP code on the server, leading to remote code execution with the privileges of the web server process. This can compromise the affected system's confidentiality, integrity, and availability.
Mitigation Recommendations
A fix is available in Laravel-Mediable version 7.0.2 and later. Users should upgrade to version 7.0.2 or newer to ensure the .pht extension is properly blocked and prevent this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T18:41:40.757Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab4491ff7a7c541065fe504
Added to database: 09/23/2026, 21:48:15 UTC
Last enriched: 09/23/2026, 22:02:40 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.