VDB
Sign up
CRITICAL9.0

GHSA-ggwg-cmwp-46r5

yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key

Quick fix

GHSA-ggwg-cmwp-46r5 — yiisoft/yii2: upgrade to the fixed version with the command below.

composer require yiisoft/yii2:^2.0.52

Details

Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/yiisoft/yii2
Introduced in: 0Fixed in: 2.0.52
Fixcomposer require yiisoft/yii2:^2.0.52

References