symfony/var-exporter

symfony/var-exporter

Releases253
Frequency1 week 3 days
Last Release
Stars2.1K
Provides tools to export, instantiate, hydrate, clone and lazy-load PHP objects

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.