plank/laravel-mediable through version 6.4.0 can allow upload of a dangerous file type when an application using the package accepts or prefers a client-supplied MIME type during file upload handling. In that configuration, a remote attacker can submit a file containing executable PHP code while declaring a benign image MIME type, resulting in arbitrary file upload. If the uploaded file is stored in a web-accessible and executable location, this may lead to remote code execution. At the time of publication, no patch was available and the vendor had not responded to coordinated disclosure attempts.
Conclusion & alert: CVE-2026-4809 is rated Moderate Risk (51.3/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.20%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-22 | 0.56% | 0.20% | -0.37% |
| 2 | 2026-04-27 | 0.52% | 0.56% | +0.05% |
| 3 | 2026-04-01 | — | 0.52% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.3 | 4.0 | CRITICAL |
|
— | — | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
| 10.0 | 2.0 | HIGH |
|
10.0 | 10.0 | 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||