tecnickcom/tcpdf is vulnerable to Deserialization of Untrusted Data
91
Critical Risk
Affected versions of this package are vulnerable to deserialization of untrusted data due to a flaw in the PHAR (PHP Archive) deserialization process via stream wrappers. Version 6.9.2 addresses the issue by disabling PHAR globally, while version 6.9.3 provides a more robust solution by validating allowed protocols, enabling safer use of PHAR without fully disabling it.
You are affected if you are using a version that falls within the vulnerable range.
tecnickcom/tcpdf is vulnerable to Deserialization of Untrusted Data in versions 6.0.013 - 6.9.1.
Upgrade the tecnickcom/tcpdf library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant