{"id":"GHSA-7xr2-8ff7-6fjq","summary":"zenstruck/collection passing callable string to EntityRepository::find() and query()","details":"### Impact\nPassing _callable strings_ (ie `system`) caused the function to be executed.\n\n### Patches\nFixed in [v0.2.1](https://github.com/zenstruck/collection/releases/tag/v0.2.1).\n\n### Workarounds\nDo not allow passing user strings to `EntityRepository::find()` or `query()`.\n\n### References\n[Fix commit](https://github.com/zenstruck/collection/commit/f4b1c488206e1b1581b06fcd331686846f13f19c).\n","aliases":["CVE-2023-37473"],"modified":"2026-09-10T03:49:42.631460226Z","published":"2023-07-14T21:59:13Z","database_specific":{"cwe_ids":["CWE-74"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-07-14T21:59:13Z","nvd_published_at":"2023-07-14T21:15:09Z"},"references":[{"type":"WEB","url":"https://github.com/zenstruck/collection/security/advisories/GHSA-7xr2-8ff7-6fjq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-37473"},{"type":"WEB","url":"https://github.com/zenstruck/collection/commit/f4b1c488206e1b1581b06fcd331686846f13f19c"},{"type":"PACKAGE","url":"https://github.com/zenstruck/collection"},{"type":"WEB","url":"https://github.com/zenstruck/collection/releases/tag/v0.2.1"}],"affected":[{"package":{"name":"zenstruck/collection","ecosystem":"Packagist","purl":"pkg:composer/zenstruck/collection"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.2.1"}]}],"versions":["v0.1.0","v0.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-7xr2-8ff7-6fjq/GHSA-7xr2-8ff7-6fjq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}