CVE-2026-24765: PHPUnit Vulnerability Exposes CI/CD Pipelines to RCE
ID: 73a51c3d-341c-545c-b854-b2c046d15ece
STIX ID: report--73a51c3d-341c-545c-b854-b2c046d15ece
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-24765, CVSS 7.8) in PHPUnit's PHPT test runner allows remote code execution by unserializing attacker-controlled .coverage files during cleanup; multiple major PHPUnit versions are affected and maintainers have released patches (8.5.52, 9.6.33, 10.5.62, 11.5.50, 12.5.8). The advisory emphasizes that exploitation requires local file-write access (e.g., malicious pull requests in CI, compromised dependencies, or local access) and recommends immediate updating plus defense-in-depth controls such as ephemeral runners, restricted execution, and artifact tamper detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
