PT-2026-36488 · Unknown · Mixphp Framework

Sginnora

·

Published

2026-05-01

·

Updated

2026-05-05

·

CVE-2026-42471

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MixPHP Framework versions 2.x through 2.2.17
Description An unsafe deserialization issue exists in the sync-invoke client within the Connection.php file at line 76. The client uses the unserialize() function on data received from server responses, which can lead to client-side remote code execution (RCE) if the client connects to a malicious server. Unsafe deserialization occurs when untrusted data is used to instill an object, allowing an attacker to manipulate the object's state to execute arbitrary code.
Recommendations Update MixPHP Framework to a version later than 2.2.17.

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42471

Affected Products

Mixphp Framework