GHSA-4rm2-28vj-fj39
Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules
Quick fix
GHSA-4rm2-28vj-fj39 — dedoc/scramble: upgrade to the fixed version with the command below.
composer require dedoc/scramble:^0.13.22Details
### Impact
A remote code execution (RCE) vulnerability affects versions `0.13.2` through `0.13.21`. When documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context.
### Patches
Fixed in version `0.13.22`.
### Workarounds
If upgrading is not immediately possible:
* Restrict access to documentation endpoints (`/docs/api`, `/docs/api.json`) * Avoid using user-controlled variables inside validation rule expressions (e.g., values derived from request input) * Disable documentation endpoints in production environments if not required
These measures significantly reduce or prevent exploitability.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.13.2Fixed in: 0.13.22composer require dedoc/scramble:^0.13.22