CRITICAL9.8
GHSA-33gc-6cw9-w3g4
Deserialization of Untrusted Data in topthink/framework
Quick fix
GHSA-33gc-6cw9-w3g4 — topthink/framework: upgrade to the fixed version with the command below.
composer require topthink/framework:^6.0.9Details
ThinkPHP v6.0.8 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\Adapter.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
0Fixed in: 6.0.9Fix
composer require topthink/framework:^6.0.9