GHSA-xv8g-76mx-2rxc
HIGHCVE-2026-49970Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). Attackers can exploit the permissive character-class regex that allows both dot and slash characters combined with an ineffective trailing trim(
- Affected
- < 7.0.0
- Fixed in
- 7.0.0
- Weakness
- CWE-22
- Published
- 2026-07-13
- Source
- github