Plank · Laravel-Mediable · CVE-2026-4809
**Name of the Vulnerable Software and Affected Versions**
plank/laravel-mediable versions prior to 6.4.1
**Description**
An issue exists where the software allows the upload of dangerous file types if the application accepts or prefers a client-supplied MIME type during file upload handling. A remote attacker can bypass restrictions by submitting a file containing executable PHP code while declaring a benign image MIME type, leading to arbitrary file upload. If the uploaded file is stored in a web-accessible and executable location, this can result in remote code execution.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.