spatie/laravel-medialibrary
Packagist2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting spatie/laravel-medialibrarypage 1 of 1
- CVE-2026-48555HIGHCVSS 7.4EG 7.4✓ Fixed in 11.23.02026-05-29
vulnerable: 0.1.0 ... 9.9.1 (511 versions)
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addM…
- CVE-2026-48557HIGHCVSS 8.8EG 8.8✓ Fixed in 11.23.02026-05-29
vulnerable: 0.1.0 ... 9.9.1 (511 versions)
Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension filenames such as shell.php.jpg …
Check whether spatie/laravel-medialibrary is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for spatie/laravel-medialibrary CVEs against the assets you own.
Start Free Scan →