---
id: CVE-2026-48555
title: >-
  Spatie Laravel Media Library before version 11.23.0 contains a server-side
  request forgery vulnerability that allows remote attackers to cause the server
  to issue arbitrary outbound HTTP requests by passing user-controlled URLs to
  the ad…
summary: >-
  Spatie Laravel Media Library before version 11.23.0 contains a server-side
  request forgery vulnerability that allows remote attackers to cause the server
  to issue arbitrary outbound HTTP requests by passing user-controlled URLs to
  the ad…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: spatie
product: laravel-medialibrary
affected:
  - laravel-medialibrary < 11.23.0
published: '2026-05-29'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:18.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48555'
references:
  - url: >-
      https://github.com/spatie/laravel-medialibrary/commit/608ea03703d3887c46434f5dda6af56de6346aba
    label: disclosure@vulncheck.com
  - url: 'https://github.com/spatie/laravel-medialibrary/pull/3939'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/spatie/laravel-medialibrary/releases/tag/11.23.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/spatie-laravel-media-library-ssrf-via-addmediafromurl
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-05-29T21:37:42.719722Z'
epss: 0.00423
epssPercentile: 0.34564
ingestedAt: '2026-10-08T16:52:14.684Z'
---

## Overview

Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
