Intel

AIKIDO-2026-820389

vrana/adminer is vulnerable to Code Injection

Code InjectionGHSA-r9r5-j5q8-8c59 Published Yesterday

72

High Risk

This Affects:

PHPvrana/adminer
4.2.0 - 6.1.0
Fixed in 6.1.1
Are you affected? Scan for Free

TL;DR

Adminer's SQLite filter blocks ATTACH and VACUUM INTO statements with a regex that only matches the keyword after Adminer's own notion of whitespace or comments, before the query reaches connection()->multi_query($q). A statement prefixed with a UTF-8 byte order mark (EF BB BF) does not match that regex, but SQLite strips the BOM and runs the statement anyway. An authenticated SQLite user can use ATTACH DATABASE to create a SQLite file at an arbitrary PHP writable path and embed PHP code in a table name, which runs when that path is requested through the web server. The fix adds a SQLite authorizer that rejects file writing ATTACH and VACUUM INTO operations regardless of a BOM prefix.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you grant an authenticated user SQLite access on a PHP process that can write files into a web served directory.

Background info

vrana/adminer is vulnerable to Code Injection in versions 4.2.0 - 6.1.0.

How to fix this

Upgrade the vrana/adminer library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform