CVE-2026-24765 is a high-severity vulnerability in PHPUnit versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52, affecting PHPUnit and Debian distributions. It involves unsafe deserialization of code coverage data in PHPT test execution, specifically in the cleanupForCoverage() method, which can lead to remote code execution. An attacker with local file write access can place a malicious serialized object, triggering arbitrary code execution during test runs with code coverage instrumentation enabled. The CVSS score is 7.8 (HIGH), indicating a local attack vector with low complexity, leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.5.52CPE matchmatch criteria | cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* | ||
>= 9.0.0, < 9.6.33CPE matchmatch criteria | cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* | ||
>= 10.0.0, < 10.5.62CPE matchmatch criteria | cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* | ||
>= 11.0.0, < 11.5.50CPE matchmatch criteria | cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* | ||
>= 12.0.0, < 12.5.8CPE matchmatch criteria | cpe:2.3:a:phpunit_project:phpunit:*:*:*:*:*:-:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.