CVE-2026-48555: Spatie Laravel Media Library contains a server-side request forgery vulnerability
(updated )
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.
References
- github.com/advisories/GHSA-fggg-964j-3j7h
- github.com/spatie/laravel-medialibrary/commit/608ea03703d3887c46434f5dda6af56de6346aba
- github.com/spatie/laravel-medialibrary/pull/3939
- github.com/spatie/laravel-medialibrary/releases/tag/11.23.0
- nvd.nist.gov/vuln/detail/CVE-2026-48555
- www.vulncheck.com/advisories/spatie-laravel-media-library-ssrf-via-addmediafromurl
Code Behaviors & Features
Detect and mitigate CVE-2026-48555 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →