CRITICAL9.8
GHSA-j2h2-g882-x9j2
Deserialization of Untrusted Data in thinkphp
Details
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/topthink/think
Introduced in:
0No fixed version published yet for topthink/think (composer). Pin to a known-safe version or switch to an alternative.