CRITICAL🇵🇱 Wersja polska

CVE-2026-25237

CVSS 9.2v4.0pub. 2026-02-03upd. 2026-02-05

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue has been patched in version 1.33.0.

🤖 AI Analysis
How it works

The vulnerability results from the use of the preg_replace() function with the /e modifier in code handling email notifications about bug reports. The /e modifier causes the replacement string to be evaluated as PHP code. If an attacker is able to supply controlled content to the replacement expression (e.g., through a crafted bug report), it will be executed as PHP code on the server.

Impact

An attacker can gain the ability to execute arbitrary PHP code remotely on the server (RCE), which consequently may lead to complete system compromise, data theft, or further lateral movement in the infrastructure.

Mitigation & patch

PEAR Pearweb should be updated to version 1.33.0 or newer, where the issue has been fixed. Detailed information is available in the vendor references: https://github.com/pear/pearweb/security/advisories/GHSA-vhw6-hqh9-8r23

Who is affected

PEAR Pearweb in versions earlier than 1.33.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Pear Pearweb

    APP
    Pear
    < 1.33.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-25241CRITICAL9.3PL ✓same product

SQL injection w PEAR Pearweb — nieuwierzytelniony dostęp przez endpoint /get/

CVE-2026-25238CRITICAL9.2PL ✓same product

SQL Injection w PEAR Pearweb — podatność przy usuwaniu subskrypcji błędów

CVE-2026-25235HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable ...

CVE-2026-25233HIGH7.1same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in...

CVE-2026-25239HIGH8.2same product

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL inject...