Beyond patching, the maintainers' approach offers good lessons. Instead of only sanitizing the input, the fix now treats a pre-existing .coverage file as an ERROR. This makes tampering visible and necessitates an investigation!
Fellow builders, check your configs and stay safe!
🧵
🚨Security Alert for PHP developers using PHPUnit!
A high-severity vulnerability (CVE-2026-24765) is reported in PHPUnit. If your CI/CD runs PHPT tests with code coverage, an attacker could achieve Remote Code Execution.
#php#security#infosec
Strettch Cloud is the future of Africa’s digital independence. By keeping our data and computing local, we reduce latency and keep wealth in our economy. Let's build the future of Rwanda, one compute at a time.
@StrettchCloud#SovereignCloud#AfricaTech
I’ve open-sourced the script and a quick-start guide on GitHub. It even injects a custom health-check page so you know your deployment worked instantly.
Check the repo here: https://t.co/qiqnJhnnAe
I also created a simple video for how to use my script:
https://t.co/mFW9TUpRU4