Unknown · Laravel-Mediable · CVE-2026-93352
**Name of the Vulnerable Software and Affected Versions**
Laravel-Mediable versions 7.0.0 through 7.0.1
**Description**
An incomplete patch in the forbidden extensions blocklist within `config/mediable.php` allows the upload of files with the `.pht` extension. While other PHP-related extensions are blocked, the omission of `.pht` allows files to pass validation in the `verifyExtension()` function of `MediaUploader` and the `sanitizeFileName()` function of `File`. On Debian and Ubuntu systems, Apache executes `.pht` files as PHP by default via the `FilesMatch` directive. This allows an attacker to upload and execute a malicious file, leading to remote code execution with the privileges of the web server process.
**Recommendations**
Update Laravel-Mediable to version 7.0.2.
As a temporary mitigation, manually add the `.pht` extension to the `forbidden extensions` blocklist in `config/mediable.php`.