---
id: CVE-2026-49970
title: >-
  Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the
  File::sanitizePath() function that allows attackers to write uploaded files to
  arbitrary locations by controlling the directory argument passed to
  MediaUploader…
summary: >-
  Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the
  File::sanitizePath() function that allows attackers to write uploaded files to
  arbitrary locations by controlling the directory argument passed to
  MediaUploader…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: plank
product: laravel-mediable
affected:
  - laravel-mediable < 7.0.0
published: '2026-07-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:19.037'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-49970'
references:
  - url: >-
      https://github.com/plank/laravel-mediable/commit/6d1e7fb39922fdfb3b2d120e13f4eb2e653ae082
    label: disclosure@vulncheck.com
  - url: 'https://github.com/plank/laravel-mediable/releases/tag/7.0.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/laravel-mediable-path-traversal-via-file-sanitizepath
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-07-14T13:19:43.970735Z'
epss: 0.01026
epssPercentile: 0.62474
ingestedAt: '2026-10-08T16:52:14.698Z'
---

## Overview

Laravel-Mediable before 7.0.0 contains a path traversal vulnerability in the File::sanitizePath() function that allows attackers to write uploaded files to arbitrary locations by controlling the directory argument passed to MediaUploader::toDestination(). Attackers can exploit the permissive character-class regex that allows both dot and slash characters combined with an ineffective trailing trim() call to bypass sanitization and upload files to sensitive locations such as the document root, environment configuration files, or application configuration directories, enabling remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
