Intel

AIKIDO-2025-10262

tecnickcom/tcpdf is vulnerable to Deserialization of Untrusted Data

Deserialization of Untrusted Data Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 22, 2025

91

Critical Risk

This Affects:

PHPtecnickcom/tcpdf
6.0.013 - 6.9.1
Fixed in 6.9.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to deserialization of untrusted data due to a flaw in the PHAR (PHP Archive) deserialization process via stream wrappers. Version 6.9.2 addresses the issue by disabling PHAR globally, while version 6.9.3 provides a more robust solution by validating allowed protocols, enabling safer use of PHAR without fully disabling it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

tecnickcom/tcpdf is vulnerable to Deserialization of Untrusted Data in versions 6.0.013 - 6.9.1.

How to fix this

Upgrade the tecnickcom/tcpdf library to the patch version.