All verified exploits

CVE-2026-4809 Arbitrary File Upload via Forged MIME Type

Pentest critical Laravel Mediable Added cve-verified-cve-2026-4809

Detects Laravel apps using plank/laravel-mediable <= 6.4.0 with prefer_client_mime_type enabled. An attacker uploads a PHP webshell with Content-Type: image/jpeg, bypassing all server-side MIME validation. If stored in a web-accessible directory with PHP execution, this achieves remote code execution. No patch available — vendor unresponsive. Mitigation: set prefer_client_mime_type to false.

Is your app exploitable through CVE-2026-4809?

Scan your domain free