CVE-2026-49969

Laravel-Mediable before 7.0.0 contains a server-side request forgery vulnerability that allows remote attackers to issue arbitrary HTTP requests from the server by supplying unvalidated caller-controlled URLs to endpoints backed by MediaUploader::fromSource(). Attackers can craft URLs targeting RFC-1918 addresses, loopback interfaces, cloud metadata endpoints, or file:// URIs through RemoteUrlAdapter to reach internal infrastructure, retrieve sensitive files, and exfiltrate cloud credentials such as IAM tokens from instance metadata services.
Configurations

No configuration.

History

13 Jul 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 19:17

Updated : 2026-07-15 15:16


NVD link : CVE-2026-49969

Mitre link : CVE-2026-49969

CVE.ORG link : CVE-2026-49969


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)