CVE-2026-33687Disclosure(code16 / sharp)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch code16 sharp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass all file type restrictions. The upload endpoint within the `ApiFormUploadController` accepts a client-controlled `validation_rule` parameter. This parameter is directly passed into the Laravel validator without sufficient server-side enforcement. By intercepting the request and sending `validation_rule[]=file`, an attacker can completely bypass all MIME type and file extension restrictions. This issue has been addressed in version 9.20.0 by removing the client-controlled validation rules and strictly defining upload rules server-side. As a workaround, ensure that the storage disk used for Sharp uploads is strictly private. Under default configurations, an attacker cannot directly execute uploaded PHP files unless a public disk configuration is explicitly used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sharp

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-26); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sharp

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-26: 2Technical Details · 2026-03-27: 103-2603-27
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-262
Disclosure1Patch1
2026-03-271
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33687 Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authe… https://www.cve.org/CVERecord?id=CVE-2026-33687

    Post summary

    CVE-2026-33687 is disclosed as a flaw in Sharp CMS file‑upload handling for versions before 9.20.0, with a patch available in 9.20.0 and later.

    00000123
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33687: HIGH] Vulnerability in Sharp's file upload endpoint (versions < 9.20.0) allows bypassing file type restrictions. Update to v9.20.0 or restrict storage disk access for uploads.#cve,CVE-2026-33687,#cybersecurity https://cvefind.com/CVE-2026-33687

    Post summary

    The post announces CVE‑2026‑33687, detailing a file‑type restriction bypass in Sharp versions prior to 9.20.0, and recommends upgrading or restricting disk access to mitigate the vulnerability.

    0000046
    617 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33687 - High Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 contain a vulnerability in the file upload endpoint that allows authenticated users to bypass ... https://www.thehackerwire.com/vulnerability/CVE-2026-33687/ https://t.co/D7o4Yo8Nbd

    Post summary

    The post announces a high‑severity vulnerability (CVE-2026-33687) in the Sharp Laravel CMS package, noting that versions older than 9.20.0 have a file‑upload bypass allowing authenticated users to exploit it.

    0000038
    163 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcode16sharp---

Explore more