PT-2026-41129 · Git+2 · Setup-Php+1
CVE-2026-46420
·
Published
2026-05-14
·
Updated
2026-08-18
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
shivammathur/setup-php versions 2.25.0 through 2.37.0
Description
Command injection is possible when the action resolves the PHP version from repository-controlled files and incorporates these values into generated shell or PowerShell setup scripts without sufficient constraint. The affected files include
.php-version, composer.lock (via platform-overrides.php), and composer.json (via config.platform.php). This issue is exploitable in trusted contexts, such as the pull request target workflow, when attacker-controlled repository contents are checked out before the action is invoked, allowing the execution of arbitrary commands on the GitHub Actions runner.Recommendations
Update shivammathur/setup-php to version 2.37.1.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Setup-Php
Shivammathur/Setup-Php