<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 03:29:34 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-267022</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-267022</link>
      <description>EUVD-2026-267022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-267022</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25129</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25129</link>
      <description>&lt;p&gt;PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim&amp;#39;s context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation. This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious `.psysh.php`, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (`php artisan tinker`) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the `.psysh.php` auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges. Versions 0.11.23 and 0.12.19 patch the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim&amp;#39;s context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation. This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious `.psysh.php`, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (`php artisan tinker`) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the `.psysh.php` auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges. Versions 0.11.23 and 0.12.19 patch the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25129</guid>
    </item>
    <item>
      <title>GHSA-4486-gxhx-5mg7 — PsySH has Local Privilege Escalation via CWD .psysh.php auto-load</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4486-gxhx-5mg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: psy/psysh&lt;/p&gt;
&lt;p&gt;### Summary
PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim&amp;#39;s context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Details
PsySH supports per-directory configuration via a `.psysh.php` file located in the process CWD. This file is executed implicitly when PsySH starts, without requiring explicit opt-in and without validating that the file and directory are safe (e.g., owned by the current user and not group/world-writable).&lt;/p&gt;
&lt;p&gt;This enables a CWD poisoning scenario: a low-privileged user can plant a malicious `.psysh.php` in any directory they can write to, then wait for a higher-privileged user to start PsySH while their shell is in that directory.&lt;/p&gt;
&lt;p&gt;### PoC
1. As a low-privileged user, create a malicious `.psysh.php` in an attacker-writable directory (example: `/tmp`):&lt;/p&gt;
&lt;p&gt;```bash
bob@localhost:/tmp$ echo &amp;#34;&amp;lt;?php system(&amp;#39;id &amp;gt; poc.txt&amp;#39;); ?&amp;gt;&amp;#34; &amp;gt; .psysh.php
bob@localhost:/tmp# ls -lah .psysh.php
-rw-r--r-- 1 bob bob 33 Jan 28 11:17 .psysh.php
```&lt;/p&gt;
&lt;p&gt;2. As the victim user, start PsySH with CWD set to that directory and exit:&lt;/p&gt;
&lt;p&gt;```bash
root@localhost:/tmp# cd /tmp
root@localhost:/tmp# ./psysh
Psy Shell v0.12.18 (PHP 8.1.2-1ubuntu2.23 — cli) by Justin Hileman
New PHP manual is available (latest: 3…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: psy/psysh&lt;/p&gt;
&lt;p&gt;### Summary
PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim&amp;#39;s context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Details
PsySH supports per-directory configuration via a `.psysh.php` file located in the process CWD. This file is executed implicitly when PsySH starts, without requiring explicit opt-in and without validating that the file and directory are safe (e.g., owned by the current user and not group/world-writable).&lt;/p&gt;
&lt;p&gt;This enables a CWD poisoning scenario: a low-privileged user can plant a malicious `.psysh.php` in any directory they can write to, then wait for a higher-privileged user to start PsySH while their shell is in that directory.&lt;/p&gt;
&lt;p&gt;### PoC
1. As a low-privileged user, create a malicious `.psysh.php` in an attacker-writable directory (example: `/tmp`):&lt;/p&gt;
&lt;p&gt;```bash
bob@localhost:/tmp$ echo &amp;#34;&amp;lt;?php system(&amp;#39;id &amp;gt; poc.txt&amp;#39;); ?&amp;gt;&amp;#34; &amp;gt; .psysh.php
bob@localhost:/tmp# ls -lah .psysh.php
-rw-r--r-- 1 bob bob 33 Jan 28 11:17 .psysh.php
```&lt;/p&gt;
&lt;p&gt;2. As the victim user, start PsySH with CWD set to that directory and exit:&lt;/p&gt;
&lt;p&gt;```bash
root@localhost:/tmp# cd /tmp
root@localhost:/tmp# ./psysh
Psy Shell v0.12.18 (PHP 8.1.2-1ubuntu2.23 — cli) by Justin Hileman
New PHP manual is available (latest: 3…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4486-gxhx-5mg7</guid>
    </item>
  </channel>
</rss>
