PKSA-5jz8-6tcw-pbk4 Security Advisory
-
[HIGH] Argument injection via newline in PHP INI values forwarded to child processes
PKSA-5jz8-6tcw-pbk4 CVE-2026-41570 GHSA-qrr6-mg7r-m243
Affected package: phpunit/phpunit
Affected version: >=12.5.21,<12.5.22|>=13.1.5,<13.1.6
Reported by:
GitHub, FriendsOfPHP/security-advisories