utopia-php/framework is vulnerable to Remote Code Execution (RCE)
88
High Risk
Affected versions of the package are vulnerable to remote code execution (RCE). If a request parameter contains a callable value such as explode, phpinfo, or any other invocable entity, utopia-php/framework may attempt to invoke it during request handling. This can allow attackers to execute arbitrary code by supplying malicious input, due to insufficient validation of request-derived callables.
You are affected if you are using a version which is within vulnerability ranges.
utopia-php/framework is vulnerable to Remote Code Execution (RCE) in versions 0.20.0 - 0.34.6.
Upgrade the utopia-php/framework library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant