top of page
perceptive_background_267k.jpg

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data received from t…

Published:

30 april 2026 om 22:00:00

Alert date:

1 mei 2026 om 20:05:47

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A critical unsafe deserialization vulnerability exists in MixPHP Framework versions 2.x through 2.2.17. The vulnerability is located in the sync-invoke client component at Connection.php line 76, where unserialize() is called on data received from server responses. This flaw enables remote code execution (RCE) on the client side when connecting to a malicious server. The vulnerability affects all versions in the 2.x branch up to and including version 2.2.17. Exploitation requires the client to connect to an attacker-controlled server that sends malicious serialized data.

Technical details

Mitigation steps:

Affected products:

MixPHP Framework

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page