PT-2026-5440 · Unknown+1 · Laravel Tinker+1

Aqhmal

·

Publicado

2026-01-30

·

Atualizado

2026-02-27

·

CVE-2026-25129

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PsySH versions prior to 0.11.23 PsySH versions prior to 0.12.19
Description PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a .psysh.php file from the Current Working Directory (CWD) on startup. An attacker who can write to a directory that a victim later uses as their CWD when launching PsySH can trigger arbitrary code execution in the victim's context. This is a CWD configuration poisoning issue. If a privileged user launches PsySH with CWD set to an attacker-writable directory containing a malicious .psysh.php, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH, such as Laravel Tinker, inherit this risk.
Recommendations Update PsySH to version 0.11.23 or later. Update PsySH to version 0.12.19 or later.

Exploit

Correção

LPE

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25129
GHSA-4486-GXHX-5MG7

Produtos afetados

Laravel Tinker
Psysh