CYBERHAWK / CVE / CVE-2026-48557

CVE-2026-48557

Spatie Laravel Media Library

HIGH CVSS 8.8 vibe

The flaw

File upload restriction bypass allows uploading malicious files with double extensions like shell.php.jpg.

What to do

Update to version 11.23.0 or later

▸ Scan my repo for CVE-2026-48557

References

First seen 2026-06-05 · Tracked by PickBits CyberHawk · Weekly CVE digest