Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-48500— Filament: Unauthenticated temporary file upload on auth pages

CVSS 6.5 · Medium EPSS 0.21% · P11
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-48500

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Filament: Unauthenticated temporary file upload on auth pages
Source: NVD (National Vulnerability Database)
Vulnerability Description
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire's WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application's temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制缺失
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
filamentphpfilament >= 3.0.0, < 3.3.52 -

II. Public POCs for CVE-2026-48500

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48500

登录查看更多情报信息。

Other References for CVE-2026-48500 (1)

Same Patch Batch · filamentphp · 2026-06-22 · 6 CVEs total

CVE-2026-554097.6 HIGHFilament: Disabled RichEditor field state can be used for XSS
CVE-2026-485057.4 HIGHFilament: Multi-factor authentication (app) recovery codes can still be used multiple time
CVE-2026-480676.5 MEDIUMFilament: Inconsistent scope enforcement for AttachAction and AssociateAction Select field
CVE-2026-481676.4 MEDIUMFilament: Unvalidated ImageColumn and ImageEntry values can be used for XSS
CVE-2026-481665.3 MEDIUMFilament: Timing-based user enumeration on login page

IV. Related Vulnerabilities

V. Comments for CVE-2026-48500

No comments yet


Leave a comment