Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-24739

Опубликовано: 28 янв. 2026
Источник: nvd
CVSS3: 6.3
EPSS Низкий

Описание

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably =) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windows executables, MSYS2’s argument/path conversion can mis-handle unquoted arguments containing these characters. This can cause the spawned process to receive corrupted/truncated arguments compared to what Symfony intended. If an application (or tooling such as Composer scripts) uses Symfony Process to invoke file-management commands (e.g. rmdir, del, etc.) with a path argument containing =, the MSYS2 conversion layer may alter the argument at runtime. In affected setups this can result in operations being performed on an unintended path, up to and including deletion of the contents

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия до 5.4.51 (исключая)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 6.4.0 (включая) до 6.4.33 (исключая)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 7.3.0 (включая) до 7.3.11 (исключая)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 7.4.0 (включая) до 7.4.5 (исключая)
cpe:2.3:a:sensiolabs:symfony:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.0.5 (исключая)

EPSS

Процентиль: 0%
0.00006
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-88

Связанные уязвимости

CVSS3: 6.3
debian
7 дней назад

Symfony is a PHP framework for web and console applications and a set ...

CVSS3: 6.3
github
6 дней назад

Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows

EPSS

Процентиль: 0%
0.00006
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-88