Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-93352: Laravel-Mediable lets uploaded .pht files execute
CVE-2026-93352 · published 16 days ago
Summary
The Laravel-Mediable package (versions 7.0.0 through 7.0.1) does not block files with a .pht extension. Because web servers on Debian and Ubuntu treat .pht files as PHP code, an attacker could upload a malicious .pht file, have it saved on the server, and then run it, gaining the same rights as the web server. Update the package to version 7.0.2 or later, or add .pht to the forbidden file extensions list, to stop this behavior.
What to do
- Update plank laravel-mediable to version 7.0.2 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| plank | laravel-mediable | < 7.0.2 |
Original advisory text
Laravel-Mediable 7.0.0 < 7.0.2 RCE via .pht File Upload
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
References
- https://github.com/plank/laravel-mediable/commit/8ddb0e5b300084e91ad2cb18a6e7bc7...
- https://github.com/plank/laravel-mediable/pull/396
- https://github.com/plank/laravel-mediable/releases/tag/7.0.2
- https://www.vulncheck.com/advisories/laravel-mediable-rce-via-pht-file-upload
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93352... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-93352 Vendor Advisory
- https://github.com/plank/laravel-mediable Product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.3
Critical
Type
CWE-434Unrestricted File Upload
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta