VDB
Sign up
CRITICAL9.4

GHSA-4rm2-28vj-fj39

Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules

Quick fix

GHSA-4rm2-28vj-fj39 — dedoc/scramble: upgrade to the fixed version with the command below.

composer require dedoc/scramble:^0.13.22

Details

### Impact

A remote code execution (RCE) vulnerability affects versions `0.13.2` through `0.13.21`. When documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context.

### Patches

Fixed in version `0.13.22`.

### Workarounds

If upgrading is not immediately possible:

* Restrict access to documentation endpoints (`/docs/api`, `/docs/api.json`) * Avoid using user-controlled variables inside validation rule expressions (e.g., values derived from request input) * Disable documentation endpoints in production environments if not required

These measures significantly reduce or prevent exploitability.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/dedoc/scramble
Introduced in: 0.13.2Fixed in: 0.13.22
Fixcomposer require dedoc/scramble:^0.13.22

References