FixedGHSA-7qpv-r5mr-78m4(SQL injection via E'...' backslash breakout). (CVE-2026-17543)
Phar:
Fixed inconsistent handling of the magic ".phar" directory. Paths such as "/.phar" remain protected, while non-magic paths that merely start with ".phar" are handled consistently across file and directory creation, copying, ArrayAccess, stream lookup, directory iteration and extraction.
Sorry, this website uses features that your browser doesn't support. Upgrade to a newer version of Firefox, Chrome, Safari, or Edge and you'll be all set.
AI-powered knowledge base assistant. Press Ctrl+/ to open, Escape to close.
Knowledge Base Chat
Hello! I'm your AI assistant. Ask me anything about our knowledge base and I'll help you find the information you need.