{"id":"GHSA-4rm2-28vj-fj39","summary":"Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules","details":"### Impact\n\nA remote code execution (RCE) vulnerability affects versions `0.13.2` through `0.13.21`. When documentation endpoints are publicly accessible and validation rules reference user-controlled input, request supplied data may be evaluated during documentation generation, leading to execution of arbitrary PHP code in the application context.\n\n### Patches\n\nFixed in version `0.13.22`.\n\n### Workarounds\n\nIf upgrading is not immediately possible:\n\n* Restrict access to documentation endpoints (`/docs/api`, `/docs/api.json`)\n* Avoid using user-controlled variables inside validation rule expressions (e.g., values derived from request input)\n* Disable documentation endpoints in production environments if not required\n\nThese measures significantly reduce or prevent exploitability.","aliases":["CVE-2026-44262"],"modified":"2026-05-13T16:57:27.482589Z","published":"2026-05-06T19:54:56Z","database_specific":{"github_reviewed_at":"2026-05-06T19:54:56Z","nvd_published_at":"2026-05-12T22:16:36Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/dedoc/scramble/security/advisories/GHSA-4rm2-28vj-fj39"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44262"},{"type":"PACKAGE","url":"https://github.com/dedoc/scramble"},{"type":"WEB","url":"https://github.com/dedoc/scramble/releases/tag/v0.13.22"}],"affected":[{"package":{"name":"dedoc/scramble","ecosystem":"Packagist","purl":"pkg:composer/dedoc/scramble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.13.2"},{"fixed":"0.13.22"}]}],"versions":["v0.13.10","v0.13.11","v0.13.12","v0.13.13","v0.13.14","v0.13.15","v0.13.16","v0.13.17","v0.13.18","v0.13.19","v0.13.2","v0.13.20","v0.13.21","v0.13.3","v0.13.4","v0.13.5","v0.13.6","v0.13.7","v0.13.8","v0.13.9"],"database_specific":{"last_known_affected_version_range":"\u003c= 0.13.21","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-4rm2-28vj-fj39/GHSA-4rm2-28vj-fj39.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L"}]}