CVE-2026-25129 Details
Description
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation. This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious `.psysh.php`, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (`php artisan tinker`) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the `.psysh.php` auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges. Versions 0.11.23 and 0.12.19 patch the issue.
A vulnerability in PsySH, a runtime developer console for PHP, allows for local privilege escalation through a CWD configuration poisoning issue. Prior to versions 0.11.23 and 0.12.19, PsySH automatically executed a `.psysh.php` file from the Current Working Directory on startup. If an attacker could write to a directory that a victim later used as their CWD when launching PsySH, they could execute arbitrary code in the victim's context. This issue is particularly concerning when PsySH is run with elevated privileges, such as root, as it allows for unauthorized access to those privileges. The vulnerability also affects downstream consumers that embed PsySH, like Laravel Tinker, when invoked from an attacker-writable CWD.
Users should upgrade to PsySH versions 0.11.23 or 0.12.19, both of which address this vulnerability. After upgrading, PsySH requires explicit trust before loading local configuration files, binaries, or Composer autoloads from untrusted projects. This can be managed with the `trustProject` configuration option, the `--trust-project` or `--no-trust-project` CLI flags, or the `PSYSH_TRUST_PROJECT` environment variable.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bobthecow/psysh/releases/tag/v0.11.23 | [email protected] | ProductRelease Notes |
| https://github.com/bobthecow/psysh/releases/tag/v0.12.19 | [email protected] | ProductRelease Notes |
| https://github.com/bobthecow/psysh/security/advisories/GHSA-4486-gxhx-5mg7 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-427 | Uncontrolled Search Path Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| psysh psysh | < 0.11.23 >= 0.12.0, < 0.12.19 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Jan 30, 2026 | New CVE Received | [email protected] |