logo

CVE-2026-24765: PHPUnit Vulnerability Exposes CI/CD Pipelines to RCE

ID: 73a51c3d-341c-545c-b854-b2c046d15ece

STIX ID: report--73a51c3d-341c-545c-b854-b2c046d15ece

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-24765, CVSS 7.8) in PHPUnit's PHPT test runner allows remote code execution by unserializing attacker-controlled .coverage files during cleanup; multiple major PHPUnit versions are affected and maintainers have released patches (8.5.52, 9.6.33, 10.5.62, 11.5.50, 12.5.8). The advisory emphasizes that exploitation requires local file-write access (e.g., malicious pull requests in CI, compromised dependencies, or local access) and recommends immediate updating plus defense-in-depth controls such as ephemeral runners, restricted execution, and artifact tamper detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.