Intel

AIKIDO-2025-10444

prism-php/prism is vulnerable to Incorrect Permission Assignment for Critical Resource

Incorrect Permission Assignment for Critical Resource Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 8, 2025

50

Medium Risk

This Affects:

PHPprism-php/prism
0.1.0 - 0.78.0
Fixed in 0.79.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package enable the Prism server by default in new installations without access restrictions, exposing it to the entire internet. Attackers can exploit these open servers to perform unauthorized actions, such as consuming resources or executing malicious operations. This misuse can lead to significant financial costs for the server owner due to excessive resource consumption or service abuse.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

prism-php/prism is vulnerable to Incorrect Permission Assignment for Critical Resource in versions 0.1.0 - 0.78.0.

How to fix this

Upgrade the prism-php/prism library to a patch version or set PRISM_SERVER_ENABLED config to false.