CRITICAL9.8
GHSA-g377-x8rg-c9mf
Deserialization of Untrusted Data in topthink/framework
Details
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendor\league\flysystem-cached-adapter\src\Storage\AbstractCache.php. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/framework
Introduced in:
0No fixed version published yet for topthink/framework (composer). Pin to a known-safe version or switch to an alternative.