CVE-2026-49969
HIGHLaravel-Mediable < 7.0.0 SSRF via RemoteUrlAdapter URL Handling
Title source: cnaDescription
Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can craft URLs targeting RFC-1918 addresses, loopback interfaces, cloud metadata endpoints, or file:// URIs through RemoteUrlAdapter to reach internal infrastructure, retrieve sensitive files, and exfiltrate cloud credentials such as IAM tokens from instance metadata services.
References (3)
Core 3
Core References
Release Notes release-notes
patch
Release Notes
https://github.com/plank/laravel-mediable/releases/tag/7.0.0
Patch patch
Patch Commit
https://github.com/plank/laravel-mediable/commit/7e9e3000fa05fe16e678f15bfb51a091e60c2cb8
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/laravel-mediable-ssrf-via-remoteurladapter-url-handling
Scores
CVSS v3
7.4
EPSS
0.0024
EPSS Percentile
15.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
plank/laravel-mediable
< 7.0.0
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026