CVE-2026-49970 HIGH

CVE-2026-49970: Laravel-Mediable < 7.0.0 Path Traversal via File::sanitizePath()

Vendor Plank
Product laravel-mediable
Weakness CWE-22 · Path traversal
Published July 13, 2026
Last update July 14, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). Attackers can exploit the permissive character-class regex that allows both dot and slash characters combined with an ineffective trailing trim() call to bypass sanitization and upload files to sensitive locations such as the document root, environment configuration files, or application configuration directories, enabling remote code execution.

Key dates

02Disclosure timeline

July 13, 2026 CVE published
July 14, 2026 Record updated

Related vulnerabilities

04Related CVE