


Perceptive Security
SOC/SIEM Consultancy

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the Fi…
Published:
30 april 2026 om 22:00:00
Alert date:
1 mei 2026 om 20:05:47
Source:
nvd.nist.gov
Web Technologies
A critical unsafe deserialization vulnerability affects MixPHP Framework versions 2.x through 2.2.17. The vulnerability exists in the session and cache handlers which use unserialize() function on data retrieved from the filesystem through the FileHandler object. This type of vulnerability can potentially allow attackers to execute arbitrary code by manipulating serialized data. The issue affects multiple versions of the popular PHP framework, making it a significant security concern for applications built on MixPHP. Organizations using affected versions should prioritize updating to a patched version.
Technical details
Mitigation steps:
Affected products:
MixPHP Framework
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-42473
https://gist.github.com/sgInnora/fa46386840fe978a30d7e53c458f2975
https://github.com/mix-php/mix
https://github.com/mix-php/mix/blob/v2.2.17/src/sync-invoke/src/Server.php
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
