VDB
Sign up
CRITICAL9.8

GHSA-33gc-6cw9-w3g4

Deserialization of Untrusted Data in topthink/framework

Quick fix

GHSA-33gc-6cw9-w3g4 — topthink/framework: upgrade to the fixed version with the command below.

composer require topthink/framework:^6.0.9

Details

ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/topthink/framework
Introduced in: 0Fixed in: 6.0.9
Fixcomposer require topthink/framework:^6.0.9

References