Detects Laravel apps using plank/laravel-mediable <= 6.4.0 with prefer_client_mime_type enabled. An attacker uploads a PHP webshell with Content-Type: image/jpeg, bypassing all server-side MIME validation. If stored in a web-accessible directory with PHP execution, this achieves remote code execution. No patch available — vendor unresponsive. Mitigation: set prefer_client_mime_type to false.
Is your app exploitable through CVE-2026-4809?
Scan your domain free