CVE-2026-41570

Source
https://cve.org/CVERecord?id=CVE-2026-41570
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41570.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41570
Aliases
Downstream
Published
2026-05-08T14:33:51.630Z
Modified
2026-07-15T01:48:51.041900470Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
Details

PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including autoprependfile, extension, disablefunctions, openbasedir, and others. Setting autoprependfile to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-88",
        "CWE-93"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41570.json"
}
References

Affected packages

Git / github.com/sebastianbergmann/phpunit

Affected ranges

Type
GIT
Repo
https://github.com/sebastianbergmann/phpunit
Events
Database specific
{
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:phpunit_project:phpunit:12.5.21:*:*:*:*:-:*:*",
        "cpe:2.3:a:phpunit_project:phpunit:13.1.5:*:*:*:*:-:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "= 12.5.21"
        },
        {
            "last_affected": "= 12.5.21"
        },
        {
            "introduced": "= 13.1.5"
        },
        {
            "last_affected": "= 13.1.5"
        },
        {
            "introduced": "12.5.21"
        },
        {
            "last_affected": "12.5.21"
        },
        {
            "introduced": "13.1.5"
        },
        {
            "last_affected": "13.1.5"
        }
    ]
}

Affected versions

12.*
12.5.21
13.*
13.1.5
= 12.*
= 12.5.21
= 13.*
= 13.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41570.json"