PT-2026-5440 · Unknown+1 · Laravel Tinker+1
Aqhmal
·
Publicado
2026-01-30
·
Atualizado
2026-02-27
·
CVE-2026-25129
CVSS v3.1
7.3
Alta
| Vetor | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PsySH versions prior to 0.11.23
PsySH versions prior to 0.12.19
Description
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a
.psysh.php file from the Current Working Directory (CWD) on startup. An attacker who can write to a directory that a victim later uses as their CWD when launching PsySH can trigger arbitrary code execution in the victim's context. This is a CWD configuration poisoning issue. If a privileged user launches PsySH with CWD set to an attacker-writable directory containing a malicious .psysh.php, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH, such as Laravel Tinker, inherit this risk.Recommendations
Update PsySH to version 0.11.23 or later.
Update PsySH to version 0.12.19 or later.
Exploit
Correção
LPE
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Laravel Tinker
Psysh