GHSA-h29g-c9cx-c73q

Suggest an improvement
Source
https://github.com/advisories/GHSA-h29g-c9cx-c73q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-h29g-c9cx-c73q/GHSA-h29g-c9cx-c73q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-h29g-c9cx-c73q
Published
2026-05-11T17:53:20Z
Modified
2026-05-11T18:05:41.880750Z
Summary
torrentpier has PHP Serialize Injections
Details

Summary

Hi, there. We've found PHP Serialize Injections in your project “torrentpier". According to the OWASP, it can pose a significant risk: enable an attacker to modify serialized objects in order to inject malicious data into the application code, resulting in code execution or an arbitrary reading of the file on any vulnerable system.

Details

In the attachment you can find a report with the number of vulnerabilities, their types and the vulnerable files. To view the lines of vulnerable code you may scan your project with the "PHP Secure" vulnerability scanner with a full access to it.

PoC

<img width="663" alt="Screenshot 2023-09-25 at 11 12 32 AM" src="https://user-images.githubusercontent.com/118765013/270273991-4a2c3884-3ab0-48ad-af77-3f3dbfa64e2a.png"> <img width="661" alt="Screenshot 2023-09-25 at 11 12 43 AM" src="https://user-images.githubusercontent.com/118765013/270274006-247ed9d3-2dc0-4a87-8f1f-89079c8be165.png"> <img width="664" alt="Screenshot 2023-09-25 at 11 12 53 AM" src="https://user-images.githubusercontent.com/118765013/270274018-b99d6ec2-4c5a-439f-b089-9e11345e963d.png"> <img width="662" alt="Screenshot 2023-09-25 at 11 13 13 AM" src="https://user-images.githubusercontent.com/118765013/270274023-36ecffc7-215d-41db-b3ba-6aa677e644d3.png">

About Us

We are a team of developers of the PHP Secure vulnerability scanner. First, we checked your code automatically. Then we reviewed the vulnerable code more deeply manually and felt it was necessary to report about it to you. We suggest you scanning your code and address vulnerabilities as soon as possible to prevent a potential breach.

If you have any questions, email us at support@phpsecure.net"

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-05-11T17:53:20Z",
    "cwe_ids": [
        "CWE-502"
    ],
    "severity": "CRITICAL",
    "nvd_published_at": null
}
References

Affected packages

Packagist / torrentpier/torrentpier

Package

Name
torrentpier/torrentpier
Purl
pkg:composer/torrentpier/torrentpier

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.4

Affected versions

v2.*
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.0.1
v2.3.0.2
v2.3.0.3
v2.3.1-rc1
v2.3.1
v2.4.0-alpha1
v2.4.0-alpha2
v2.4.0-alpha3
v2.4.0-alpha4
v2.4.0-beta1
v2.4.0-beta2
v2.4.0-beta3
v2.4.0-beta4
v2.4.0-rc1
v2.4.0-rc2
v2.4.0
v2.4.1
v2.4.2
v2.4.3
2.*
2.3.0.4-beta
2.3.0.4-beta2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-h29g-c9cx-c73q/GHSA-h29g-c9cx-c73q.json"
last_known_affected_version_range
"<= 2.4.3"