PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=value command-line arguments without neutralizing INI metacharacters. Because PHP's INI parser interprets " as a string delimiter, ; as the start of a comment, and most importantly a newline as a directive separator, a value containing a newline is parsed by the child process as multiple INI directives. An attacker able to influence a single INI value can therefore inject arbitrary additional directives into the child's configuration, including autoprependfile, extension, disablefunctions, openbasedir, and others. Setting autoprependfile to an attacker-controlled path yields remote code execution in the child process. This issue has been patched in versions 12.5.22 and 13.1.6.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-88",
"CWE-93"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41570.json"
}{
"source": [
"AFFECTED_FIELD",
"CPE_STRING"
],
"cpe": [
"cpe:2.3:a:phpunit_project:phpunit:12.5.21:*:*:*:*:-:*:*",
"cpe:2.3:a:phpunit_project:phpunit:13.1.5:*:*:*:*:-:*:*"
],
"extracted_events": [
{
"introduced": "= 12.5.21"
},
{
"last_affected": "= 12.5.21"
},
{
"introduced": "= 13.1.5"
},
{
"last_affected": "= 13.1.5"
},
{
"introduced": "12.5.21"
},
{
"last_affected": "12.5.21"
},
{
"introduced": "13.1.5"
},
{
"last_affected": "13.1.5"
}
]
}