Vulnerability DatabaseGHSA-26hp-cgjj-m2j3

GHSA-26hp-cgjj-m2j3
PHP vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-26hp-cgjj-m2j3) affects the ImageMagick driver in the fuel/core package, where unvalidated image filenames containing specially crafted strings could lead to OS command execution. This high-severity security issue was discovered in versions prior to 1.8.0.4 and was patched in version 1.8.0.4 (GitHub Advisory).

Technical details

The vulnerability exists in the ImageMagick driver's handling of shell arguments, where filenames passed to the driver were not properly escaped before being used in system commands. This could allow malicious input to break out of the intended command context and execute arbitrary OS commands (FuelPHP Advisory).

Impact

When exploited, this vulnerability could allow attackers to execute arbitrary operating system commands through specially crafted image filenames, potentially leading to unauthorized system access or manipulation (GitHub Advisory).

Exploitability

The vulnerability can be triggered by passing unvalidated image filenames containing specially crafted strings to the ImageMagick driver. The attack requires the ability to control the filename of images being processed by the application (FuelPHP Advisory).

Mitigation and workarounds

The issue was addressed in version 1.8.0.4 of fuel/core. Users should upgrade to this version or later to receive the security fix. The fix involves proper escaping of filenames passed to exec() commands, as implemented in commit 95c134e (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44741HIGH8.8
  • PHP logoPHP
  • pimcore/admin-ui-classic-bundle
NoYesAug 12, 2026
CVE-2026-47233MEDIUM6.5
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-47132MEDIUM5.4
  • PHP logoPHP
  • thorsten/phpmyfaq
NoYesAug 12, 2026
CVE-2026-47234MEDIUM4.4
  • PHP logoPHP
  • admidio/admidio
NoYesAug 12, 2026
CVE-2026-49262LOW3
  • PHP logoPHP
  • aimeos/pagible
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management