NVD CRITICAL: CVE-2026-93352 — Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49...
Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a .pht file tha
CVE-2026-93352