Skip to main content
Vulnerability Database/CVE-2026-93352

CVE-2026-93352: Laravel-Mediable RCE Vulnerability

CVE-2026-93352 is a remote code execution vulnerability in Laravel-Mediable that allows attackers to upload and execute malicious PHP files via the .pht extension. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-93352 Overview

CVE-2026-93352 is a remote code execution vulnerability in the Laravel-Mediable package versions 7.0.0 through 7.0.1. The flaw stems from an incomplete patch for CVE-2026-49972. Maintainers added phpt to the forbidden_extensions blocklist in config/mediable.php but omitted pht. Apache on Debian and Ubuntu executes .pht files as PHP via the default FilesMatch directive. Attackers can upload a .pht payload that bypasses MediaUploader::verifyExtension() and File::sanitizeFileName(), then trigger execution by requesting the file. The issue is classified as Unrestricted Upload of File with Dangerous Type [CWE-434].

Critical Impact

Unauthenticated attackers can achieve remote code execution as the web server user by uploading a .pht file through applications using vulnerable Laravel-Mediable releases.

Affected Products

  • Laravel-Mediable 7.0.0
  • Laravel-Mediable 7.0.1
  • Applications using the plank/laravel-mediable package on Apache with default Debian or Ubuntu PHP configuration

Discovery Timeline

  • 2026-09-23 - CVE-2026-93352 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-93352

Vulnerability Analysis

Laravel-Mediable validates uploads against a blocklist of forbidden extensions defined in config/mediable.php. The prior fix for CVE-2026-49972 added extensions such as php7, php8, phtml, phar, and phpt to the list. It failed to include pht. On Debian and Ubuntu, the shipped Apache PHP configuration uses a FilesMatch directive that maps .pht alongside .php and .phtml to the PHP handler. Any file written to a web-accessible directory with a .pht suffix is therefore executed as PHP source when requested.

Root Cause

The root cause is an incomplete denylist in config/mediable.php. MediaUploader::verifyExtension() and File::sanitizeFileName() rely on the forbidden_extensions array to reject dangerous uploads. Because pht is absent, both checks pass for a .pht file. This is a classic denylist bypass pattern under [CWE-434], where relying on an incomplete list of dangerous types leaves parallel execution handlers unprotected.

Attack Vector

An attacker submits an upload request to any application endpoint that invokes MediaUploader with attacker-controlled file input. The uploaded file uses the .pht extension and contains PHP code. The uploader writes the file to the configured media disk. When the attacker requests the resulting URL, Apache dispatches the file to the PHP interpreter and executes the embedded code under the web server account. No authentication is required if the upload endpoint is publicly reachable.

php
// Security patch in config/mediable.php
// Source: https://github.com/plank/laravel-mediable/commit/8ddb0e5b300084e91ad2cb18a6e7bc768bb7b008
         'php7',
         'php8',
         'phtml',
+        'pht',
         'phar',
         'phpt',
         'pgif',

The patch adds pht to the forbidden_extensions blocklist so that MediaUploader::verifyExtension() rejects the extension before the file reaches disk.

Detection Methods for CVE-2026-93352

Indicators of Compromise

  • Files with a .pht extension present in Laravel storage or public media directories
  • HTTP POST requests to Laravel-Mediable upload endpoints containing multipart filenames ending in .pht
  • HTTP GET requests to .pht URLs returning 200 responses with dynamic content
  • Web server processes (www-data, apache, nginx) spawning shells or outbound network connections shortly after an upload

Detection Strategies

  • Inspect the media table and configured storage disks for entries whose extension column equals pht or whose filename ends in .pht.
  • Enable and review Apache access logs for requests matching \.pht(\?|$) and correlate with prior upload activity from the same client.
  • Add web application firewall rules that block multipart uploads containing filenames matching \.pht$ case-insensitively.

Monitoring Recommendations

  • Monitor process ancestry on web servers for PHP-FPM or Apache workers launching sh, bash, python, curl, or wget.
  • Alert on file creation events under public web roots for any extension in the php*, phtml, pht, phar, or phpt families.
  • Track outbound connections initiated by the web server user to non-approved destinations following upload requests.

How to Mitigate CVE-2026-93352

Immediate Actions Required

  • Upgrade plank/laravel-mediable to version 7.0.2 or later via composer update plank/laravel-mediable.
  • Audit media storage directories for existing .pht files and remove any that are not attributable to legitimate uploads.
  • Review Apache virtual host configuration on Debian and Ubuntu hosts to confirm which extensions are mapped to the PHP handler.

Patch Information

The fix is available in Laravel-Mediable release 7.0.2. The change is implemented in commit 8ddb0e5, which adds pht to the forbidden_extensions array in config/mediable.php. Additional context is available in pull request #396 and the VulnCheck advisory.

Workarounds

  • Add pht to the forbidden_extensions array in config/mediable.php manually if upgrading is not immediately possible.
  • Configure Apache to strip PHP handler mapping for .pht files, or serve uploaded media from a separate host without a PHP interpreter.
  • Enforce an allowlist of accepted MIME types and extensions at the application layer instead of relying on the denylist alone.
bash
# Manual mitigation: extend the forbidden_extensions list in config/mediable.php
# 'forbidden_extensions' => [
#     'php', 'php3', 'php4', 'php5', 'php7', 'php8',
#     'phtml', 'pht', 'phar', 'phpt', 'pgif',
# ],

composer require plank/laravel-mediable:^7.0.2
php artisan config:clear

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.