Intel

AIKIDO-2026-574383

plank/laravel-mediable is vulnerable to Stored Cross-Site Scripting (XSS)

Stored Cross-Site Scripting (XSS)CVE-2026-49971 Published 4 days ago

61

Medium Risk

This Affects:

PHPplank/laravel-mediable
0.0.1 - 6.5.0
Fixed in 7.0.0
Are you affected? Scan for Free

TL;DR

MediaUploader::upload() and replace() store uploaded SVG files without sanitizing their contents. An SVG containing an onload handler, <script> tag, or foreignObject element is written to disk unchanged and runs in the browser when a victim opens or previews it, so the script can capture session cookies and CSRF tokens. The fix adds a pluggable sanitizer pipeline and strips executable content from SVG uploads by default through enshrined/svg-sanitize.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you allow users to upload SVG files that are later opened or previewed in a browser.

Background info

plank/laravel-mediable is vulnerable to Stored Cross-Site Scripting (XSS) in versions 0.0.1 - 6.5.0.

How to fix this

Upgrade the plank/laravel-mediable library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform