PT-2026-41129 · Git+2 · Setup-Php+1

CVE-2026-46420

·

Published

2026-05-14

·

Updated

2026-08-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions shivammathur/setup-php versions 2.25.0 through 2.37.0
Description Command injection is possible when the action resolves the PHP version from repository-controlled files and incorporates these values into generated shell or PowerShell setup scripts without sufficient constraint. The affected files include .php-version, composer.lock (via platform-overrides.php), and composer.json (via config.platform.php). This issue is exploitable in trusted contexts, such as the pull request target workflow, when attacker-controlled repository contents are checked out before the action is invoked, allowing the execution of arbitrary commands on the GitHub Actions runner.
Recommendations Update shivammathur/setup-php to version 2.37.1.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-46420
GHSA-PQWM-Q9PV-PH8R

Affected Products

Setup-Php
Shivammathur/Setup-Php