


Perceptive Security
SOC/SIEM Consultancy

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data received from t…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 20:05:47
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A critical unsafe deserialization vulnerability exists in MixPHP Framework versions 2.x through 2.2.17. The vulnerability is located in the sync-invoke client component at Connection.php line 76, where unserialize() is called on data received from server responses. This flaw enables remote code execution (RCE) on the client side when connecting to a malicious server. The vulnerability affects all versions in the 2.x branch up to and including version 2.2.17. Exploitation requires the client to connect to an attacker-controlled server that sends malicious serialized data.
Technical details
Mitigation steps:
Affected products:
MixPHP Framework
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42471
https://gist.github.com/sgInnora/fa46386840fe978a30d7e53c458f2975
https://github.com/mix-php/mix
https://github.com/mix-php/mix/blob/v2.2.17/src/sync-invoke/src/Server.php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
