PT-2026-96786 · Misp · Misp
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MISP (affected versions not specified)
Description
MISP registers the PHP phar stream wrapper in its web and console entry points. This wrapper causes PHP to treat phar archives as directories, leading to two security risks: any filesystem operation on a path influenced by a caller that resolves to a phar archive triggers an implicit
unserialize() call, creating a deserialization sink, and a relocated application root may access executable code within an uploaded phar file, allowing arbitrary code execution as the web user. The wrapper serves no legitimate purpose within the MISP runtime, the CakePHP framework, or its loaded libraries.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Special Elements Injection
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Misp