CVE-2026-33687: Sharp has Unrestricted File Upload via Client-Controlled Validation Rules
The code16/sharp Laravel admin panel package contains a vulnerability in its file upload endpoint that allows authenticated users to bypass all file type restrictions.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33687 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →