External risk intelligence

Laravel-Mediable Remote Code Execution via .pht File Upload.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-93352

The vulnerability exists in a web application framework component (Laravel-Mediable) used for file uploads. Web applications and their associated media handling features are commonly deployed as internet-facing services, making this functionality typically accessible via the public web.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in Laravel-Mediable, a component used for managing files within Laravel applications. The issue involves an incomplete security fix that could allow an attacker to upload and execute malicious PHP code on the web server by exploiting a loophole in file extension validation. This could lead to unauthorized control over the affected system.

  • Allows malicious code execution via file upload.
  • Critical flaw impacts web application integrity.
  • Confirm exposure and review affected web assets.

Attack Path

How an attacker could exploit the issue

An attacker could upload a specially crafted file to a Laravel-Mediable application. Because the application does not properly check the file extension, it may treat a `.pht` file as a PHP script. This could allow an attacker to execute arbitrary code on the server.

  • Unauthenticated network access is required.
  • Uploading a `.pht` file triggers execution.
  • Results in remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A web server process could execute arbitrary PHP code when a specially crafted `.pht` file is uploaded and then requested. This is possible because the application's file upload validation may not prevent `.pht` extensions, and certain server configurations treat `.pht` files as executable PHP scripts.

  • Web server process.
  • Uploading a malicious `.pht` file.
  • Remote code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners are likely responsible for addressing this vulnerability within the Laravel-Mediable component, as it affects file upload functionality. The first practical step is to identify all instances of Laravel-Mediable, confirm their exposure and business criticality, and then assign ownership for remediation.

  • Application owners should manage this issue.
  • Verify affected instances and exposure.
  • Plan remediation according to risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Laravel-Mediable?

Laravel-Mediable is a library designed for the Laravel PHP framework that simplifies the process of attaching and managing files associated with models in an application. It provides developers with tools to handle media uploads, storage, and retrieval, ensuring that files are organized and validated before being saved to the server.

How does CVE-2026-93352 cause a vulnerability?

This vulnerability is classified as Unrestricted Upload of File with Dangerous Type (CWE-434). It occurs because the software's file validation process relies on a blocklist that omits the .pht extension. Since specific web server configurations treat .pht files as executable PHP code, an attacker can bypass security checks to upload and run unauthorized scripts.

Do I need to be authenticated to trigger this bug?

No, unauthenticated network access is sufficient to reach the upload functionality. The bug is triggered when a user uploads a .pht file; simply accessing or viewing a standard image or document file format does not trigger the execution of malicious code, as the flaw specifically relies on the missing extension check for executable types.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal identifies this as a likely risk because Laravel-Mediable handles media uploads in web applications, which are commonly internet-facing. If your application exposes file upload features to the public web, it is inherently more accessible to potential abuse than a system restricted to an internal network.

What should I do if I use Laravel-Mediable?

First, locate all applications within your environment that depend on this library. Verify your current version, as the fix involves updating to version 7.0.2 or later to address the extension blocklist oversight. Work with your development team to prioritize this update, especially for systems that allow public file uploads.

References