CVE-2026-24739 PUBLISHED CVSS 6.300000190734863 MEDIUM

Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows

EPSS 0.01% · 0.7th percentile

Risk Scores

CVSS v3.1
6.300000190734863
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H
EPSS Score
0.01%
0.7th percentile

Affected Products

VendorProductVersions
symfonyprocess8.0, 0, 6.4
sensiolabssymfony0, 6.4.0, 7.3.0
symfonysymfony8.0, 0, 6.4
symfonysymfony< 5.4.51, >= 6.4.0, < 6.4.33, >= 7.3.0, < 7.3.11
SymfonySymfony

Timeline

References

Open in Interactive Console →