Incomplete List of Disallowed Inputs Affecting spatie/laravel-medialibrary package, versions <11.23.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Social Trends
EPSS
0.44% (35th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-SPATIELARAVELMEDIALIBRARY-17660518
  • published27 Jun 2026
  • disclosed29 May 2026
  • creditXurshidbek Sobirjonov

Introduced: 29 May 2026

CVE-2026-48557  (opens in a new tab)
CWE-184  (opens in a new tab)

How to fix?

Upgrade spatie/laravel-medialibrary to version 11.23.0 or higher.

Overview

Affected versions of this package are vulnerable to Incomplete List of Disallowed Inputs via the defaultSanitizer function in FileAdder.php. An attacker can upload files with double extensions or omitted executable extensions, potentially leading to remote code execution by bypassing file type restrictions. This can be achieved by uploading files such as shell.php.jpg or files with extensions like .php6, .shtml, or .htaccess. This is only exploitable if a legacy Apache AddHandler configuration is present, which allows execution of files with certain extensions.

CVSS Base Scores

version 4.0
version 3.1