CVE-2026-33687 describes an unrestricted file upload vulnerability in Sharp, a Laravel content management framework, affecting versions prior to 9.20.0. Authenticated users can bypass file type restrictions by manipulating a client-controlled validation parameter in the upload endpoint. This vulnerability carries a CVSSv3.1 score of 8.8 (High), indicating it is easily exploitable over the network with low privileges and no user interaction, potentially leading to high impact on confidentiality, integrity, and availability. Successful exploitation could allow attackers to upload malicious files, though direct execution of uploaded PHP files typically requires a public storage disk configuration; a recommended workaround is to ensure private storage. There is currently no evidence of active exploitation, nor are public exploit codes available, though the vulnerability has garnered limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.20.0CPE matchmatch criteria | cpe:2.3:a:code16:sharp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.