Two high-severity file upload vulnerabilities have been disclosed in Laravel ecosystem components used for content and file management. Sharp versions prior to 9.20.0 are affected by CVE-2026-33687, which lets authenticated users bypass upload restrictions by tampering with a client-controlled validation_rule parameter so the server accepts files without intended MIME type or extension checks. The issue was fixed in 9.20.0 by removing client-side control over validation and enforcing checks server-side; the advisory also notes risk is reduced when uploads are stored on a strictly private disk and that default setups do not directly execute uploaded PHP files unless a public disk is configured.
A separate disclosure, CVE-2019-25673, affects UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0, where authenticated attackers can submit multipart uploads with the type parameter set to Files, upload malicious PHP content, and then trigger arbitrary code execution by accessing the uploaded file from the working directory path. Both issues are classified as CWE-434 unrestricted file upload flaws and carry high-impact severity scores, underscoring the risk that authenticated upload features in Laravel-based management tools can be abused to place attacker-controlled files on servers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A CVE entry for an arbitrary file upload vulnerability in UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 was received by disclosure@vulncheck.com. The flaw allows authenticated attackers to upload malicious PHP files via the upload endpoint and achieve code execution by accessing the uploaded file.
Sharp addressed CVE-2026-33687 in version 9.20.0 by removing client-controlled validation rules and enforcing upload validation on the server side. The advisory also noted that using a strictly private storage disk reduces risk.
CVE-2026-33687 was recorded for Sharp, a Laravel-packaged content management framework, affecting versions prior to 9.20.0. The issue lets authenticated users bypass file type restrictions by manipulating the client-controlled validation_rule parameter in upload requests.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.