天下漏洞,尽知其名
MEDIUM

CVE-2026-48500 rimbadirgantara 代码执行漏洞

影响攻击者可执行任意代码

AI 研判

该漏洞编号为 CVE-2026-48500,涉及 rimbadirgantara 相关项目,被归类为代码执行漏洞,危害等级为 MEDIUM。目前公开信息仅指向一个 GitHub 仓库链接,缺乏厂商公告与漏洞细节。

影响范围

rimbadirgantara

受影响的具体产品与版本范围暂无公开信息,无法确认。

漏洞详情

从漏洞类型看,属于代码执行类问题,通常由对不可信输入的不安全处理(如反序列化、动态执行或命令拼接)导致,攻击者可借此在目标环境运行任意代码。但该漏洞的具体成因与利用链暂无公开信息,无法进一步说明。

利用条件与风险

利用前提条件与实战风险暂无公开信息;鉴于仅有第三方仓库链接且无权威公告,需警惕信息真实性。

修复建议

官方修复方案与临时缓解措施暂无公开信息,建议关注厂商或项目官方渠道发布的补丁与公告。

原始情报

Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies Livewire’s WithFileUploads trait to the Livewire component the schema is embedded in. However, some schemas, such as the panel login form, do not require file uploads, and exposing unauthenticated temporary file uploads on these components is not an acceptable risk. On these components, an unauthenticated attacker could upload arbitrary files to the application’s temporary storage, which could be abused to exhaust disk space or inflate storage costs. This vulnerability is fixed in 3.3.52, 4.11.5, and 5.6.5.