Filament · Filament · CVE-2026-48500
**Name of the Vulnerable Software and Affected Versions**
Filament versions prior to 3.3.52
Filament versions prior to 4.11.5
Filament versions prior to 5.6.5
**Description**
Filament applies Livewire's `WithFileUploads` trait to components where schemas may contain file upload fields. Certain schemas, such as the panel login form, do not require this functionality. This allows an unauthenticated attacker to upload arbitrary files to the application's temporary storage, which can be exploited to exhaust disk space or increase storage costs.
**Recommendations**
Update to version 3.3.52.
Update to version 4.11.5.
Update to version 5.6.5.