Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Aniket Akhade

#26490of 57,410
9.8Total CVSS
Vulnerabilities · 1
PT-2026-97605
9.8
2026-09-23
Unknown · Laravel-Mediable · CVE-2026-93352
**Name of the Vulnerable Software and Affected Versions** Laravel-Mediable versions 7.0.0 through 7.0.1 **Description** An incomplete patch in the forbidden extensions blocklist within `config/mediable.php` allows the upload of files with the `.pht` extension. While other PHP-related extensions are blocked, the omission of `.pht` allows files to pass validation in the `verifyExtension()` function of `MediaUploader` and the `sanitizeFileName()` function of `File`. On Debian and Ubuntu systems, Apache executes `.pht` files as PHP by default via the `FilesMatch` directive. This allows an attacker to upload and execute a malicious file, leading to remote code execution with the privileges of the web server process. **Recommendations** Update Laravel-Mediable to version 7.0.2. As a temporary mitigation, manually add the `.pht` extension to the `forbidden extensions` blocklist in `config/mediable.php`.